I am using Apache 1.3.29 on Windows 2000. I am using the ntlm_module for Basic Authentication. Everything works ok with the exception of the session variable. When I have users login to my webapp using the Apache authentication, it does not log them out correctly. If someone logs out, but does not close their browser, they can log right back in without being prompted for name/password. This is a security problem that I need to fix. Does anyone know how to clear this session variable or whatever is holding the authentication?
Any help appreciated!!!
-DJ
Any help appreciated!!!
-DJ