Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
Trunk
-
None
Description
The method org.ofbiz.webapp.control.LoginWorker.doBasicLogout is use userLogin without check for against null values.
userLogin is the values of request.getSession().getAttribute("userLogin") (Line 568) in Line 589 this is value is used. For the use in Line 585 there is a null pointer test.
This occurs when a user that is allready logout reloads the logout page.