Refined urltokens and XSRF protection
[project/luci.git] / modules / admin-mini / luasrc / controller / mini / index.lua
index dad6ccf..acff55a 100644 (file)
@@ -44,8 +44,9 @@ function action_logout()
        local sauth = require "luci.sauth"
        if dsp.context.authsession then
                sauth.kill(dsp.context.authsession)
+               dsp.context.urltoken.stok = nil
        end
 
-       luci.http.header("Set-Cookie", "sysauth=; path=/")
+       luci.http.header("Set-Cookie", "sysauth=; path=" .. dsp.build_url())
        luci.http.redirect(luci.dispatcher.build_url())
 end
\ No newline at end of file