Limiting sessions by adding maximum sessions value to 1 and session registry to Security Configuration
http.sessionManagement() .maximumSessions(1) .sessionRegistry(sessionRegistry()) .expiredUrl("/login?expired");