Repository navigation
Conversation
and the possibility to specify the post logout redirect uris during client registration
|
enricovianello
force-pushed
the
develop
branch
2 times, most recently
from
June 8, 2026 16:18
eb3474a to
a97cdc3
Compare
Removed a missing redirectURI validation because in any case we must rely on backend validation
|
with one created in IAM
by using the normalized client scope, which is guaranteed to be non-null by cloneSet()
for post_logout_redirect_uris validation
enricovianello
approved these changes
Oct 7, 2026
enricovianello
left a comment
Member
There was a problem hiding this comment.
LGTM. This PR adds proper RP-initiated logout support, validates the id_token_hint and associated claims before use, enforces correct post_logout_redirect_uri checks against registered client URIs, and includes focused tests. The security controls and URI validation are appropriate.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Description
This PR adds support for OpenID Connect RP-Initiated Logout specification.
Changes
OidcLogoutSuccessHandlerid_token_hintsignature and relevant claims (issandaud)id_token_hintaudiencepost_logout_redirect_uriagainst the URIs registered for the clientpost_logout_redirect_urisduring client creation and update, including dynamic client registration/updatestateparameter when redirecting the User Agent back to the RPSecurity considerations
post_logout_redirect_uriis only used when it matches a URI previously registered by the client. Theid_token_hintis validated before using its claims to identify the client.Post-logout redirect URI validation
A dedicated validator is used for
post_logout_redirect_urisinstead of reusing the existing redirect URI validator, since the RP-Initiated Logout specification defines different requirements for post-logout redirect URIs.The validator checks that:
HTTPSorHTTP);