Skip to content

Add a custom oidc logout success handler - #1180

Open
rmiccoli wants to merge 23 commits into
developfrom
issue-1179
Open

rmiccoli wants to merge 23 commits into
developfrom
issue-1179

Conversation

@rmiccoli

@rmiccoli rmiccoli commented Feb 24, 2026 •

Copy link
Copy Markdown
Contributor

Description

This PR adds support for OpenID Connect RP-Initiated Logout specification.

Changes

  • Add support for handling RP-Initiated Logout requests through OidcLogoutSuccessHandler
  • Validate the id_token_hint signature and relevant claims (iss and aud)
  • Resolve the client associated with the id_token_hint audience
  • Validate post_logout_redirect_uri against the URIs registered for the client
  • Add dedicated validation for post_logout_redirect_uris during client creation and update, including dynamic client registration/update
  • Apply the appropriate restrictions to HTTP post-logout redirect URIs
  • Preserve the state parameter when redirecting the User Agent back to the RP
  • Add tests

Security considerations

post_logout_redirect_uri is only used when it matches a URI previously registered by the client. The id_token_hint is validated before using its claims to identify the client.

Post-logout redirect URI validation

A dedicated validator is used for post_logout_redirect_uris instead of reusing the existing redirect URI validator, since the RP-Initiated Logout specification defines different requirements for post-logout redirect URIs.

The validator checks that:

  • the URI is syntactically valid and absolute;
  • the URI uses an allowed scheme (HTTPS or HTTP);
  • HTTP URIs are only allowed for confidential clients;
  • HTTP URIs are restricted to the configured allowed hosts;
  • the URI does not contain a fragment;
  • the URI is not blocked by the configured URI deny list.

and the possibility to specify the post
logout redirect uris during client registration
@rmiccoli rmiccoli linked an issue Feb 24, 2026 that may be closed by this pull request
@rmiccoli rmiccoli changed the title Add a custom oidc login success handler Add a custom oidc logout success handler Feb 24, 2026
@sonarqubecloud

Copy link
Copy Markdown

@enricovianello
enricovianello force-pushed the develop branch 2 times, most recently from eb3474a to a97cdc3 Compare June 8, 2026 16:18
@enricovianello enricovianello added the v1.14.x Pull Request with one or more bug-fixes for IAM v1.14.0 label Jun 17, 2026
@sonarqubecloud

sonarqubecloud Bot commented Jul 1, 2026

Copy link
Copy Markdown

@enricovianello enricovianello added pr:postponed This PR won't be included now. Including this PR must be re-evaluated in the future. and removed pr:under-review labels Jul 6, 2026
@enricovianello enricovianello added priority:high and removed v1.14.x Pull Request with one or more bug-fixes for IAM v1.14.0 pr:postponed This PR won't be included now. Including this PR must be re-evaluated in the future. labels Oct 1, 2026
@enricovianello enricovianello added v1.15.x Pull Request with features to add to next IAM feature release eosc It's a EOSC related fix/feature priority:normal and removed priority:high labels Oct 2, 2026

@enricovianello enricovianello left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. This PR adds proper RP-initiated logout support, validates the id_token_hint and associated claims before use, enforces correct post_logout_redirect_uri checks against registered client URIs, and includes focused tests. The security controls and URI validation are appropriate.

@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

eosc It's a EOSC related fix/feature kind/debt pr:ready priority:normal v1.15.x Pull Request with features to add to next IAM feature release

Projects

Status: Changes Requested

Development

Successfully merging this pull request may close these issues.

Implement OpenID Connect RP-Initiated Logout

2 participants