-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
signOut function does not call endsession endpoint #7
Comments
So the suggestion is to call That seems like a reasonable suggestion, I’m happy to make the changes in the next day or two. |
@minkas-g-d I've made some changes to accommodate this functionality. I haven't tested it fully yet, but the changes are published under the Note that you will need to add the "end session" route to your application and render the |
Hi, @thchia . Tried to figure out where is the problem but with no success for the moment. |
@minkas-g-d Aside from the above issue you just mentioned, I've done more digging into the OpenID spec. It seems that the I'm not sure that this should be the default behaviour. In my experience, logging out from a client application does not log me out of the Identity Provider. We can consider adding additional functionality to support this, but it seems like the changes I made are now redundant. Please feel free to advise if you are more familiar with the OpenID spec and I'm misunderstanding something. * Additionally, some Identity Providers (incidentally, Google included) do not support this action. |
Hi, @thchia! Cannot say that I am better acquainted with the OpenID spec. |
@minkas-g-d I've just been looking at the spec. I understand your use case better now, but given that not all OPs support this "single sign-out" functionality, I am inclined to leave the functionality as-is for now. I tested this yesterday using Google and it did not work. I will continue to investigate how to detect whether single sign-out is supported so that I can automatically redirect if it is. Can I ask that you continue to implement the redirection in userland for now? |
Yes, of course. Thanks for the efforts. |
Will track this in #11 |
What signOut does is to call userManager.removeUser() and nothing else.
I would expect to redirect and end the session of the user.
Currently I am using userManager.signoutRedirect method to sing out from Identity server.
The text was updated successfully, but these errors were encountered: