Member Logout and Session Cleanup

Logout removes authenticated session state and invalidates the session cookie. Because logout changes server-side state, a POST action with CSRF protection is preferable for production applications.

Logout Form Top ↑

<form action="mem-logout.php"
      method="post">
  <input type="hidden"
         name="csrf_token"
         value="...">
  <button type="submit"
          class="btn btn-outline-danger">
    Logout
  </button>
</form>

Clear Session Data Top ↑

$_SESSION = [];

if (
    ini_get(
        'session.use_cookies'
    )
) {
    $params =
        session_get_cookie_params();

    setcookie(
        session_name(),
        '',
        time() - 42000,
        $params['path'],
        $params['domain'],
        $params['secure'],
        $params['httponly']
    );
}

session_destroy();

Validate the CSRF token before clearing the session in a production POST logout handler.

After Logout Top ↑

Redirect to login or a public page and confirm that the user has signed out. Do not print old session values or the session ID as part of the logout confirmation.

header(
    'Location: mem-login.php?logged_out=1'
);
exit;

Legacy Simpler Pattern Top ↑

session_unset() plus session_destroy() clears server session state, but a complete logout should also clear the session cookie when PHP sessions use cookies.

See PHP sessions.

Original Source Examples Retained for Migration Reference Top ↑

Historical code: these source-page examples are retained so no learner-purpose example is silently lost. Use the modern secure patterns above for new work.

Original example 1

session_unset();
session_destroy();

Additional Original Learning Routes Top ↑






plus2net.com






✖
We use cookies to improve your browsing experience. . Learn more
HTML MySQL PHP JavaScript ASP Photoshop Articles Contact us
© 2000-2026 plus2net.com All rights reserved worldwide Privacy Policy Disclaimer