Skip to content

fix(oauth): signing out of INITE signs the user out of the relying parties - #207

Merged
Mikefluff merged 1 commit into
mainfrom
fix/logout-ends-rp-sessions
Sep 27, 2026
Merged

Mikefluff merged 1 commit into
mainfrom
fix/logout-ends-rp-sessions

Conversation

@Mikefluff

Copy link
Copy Markdown
Member

/oauth/logout destroyed the IdP session and sent back-channel logout tokens,
but only to RPs that registered a URI, and left every refresh token alive. An
RP without a URI (mikefluff.com, for one) kept the user signed in for as long
as its refresh token lived, which is what a user who has just signed out
reads as "it did not work".

The user's refresh tokens are now revoked after the fan-out (which selects its
recipients by those tokens). Refresh tokens are not bound to an IdP session,
so this is every device, matching the sub-level logout_token.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_01FdVXRzoHDTGciZtVhbhy8y

…rties

/oauth/logout destroyed the IdP session and sent back-channel logout tokens,
but only to RPs that registered a URI, and left every refresh token alive. An
RP without a URI (mikefluff.com, for one) kept the user signed in for as long
as its refresh token lived, which is what a user who has just signed out
reads as "it did not work".

The user's refresh tokens are now revoked after the fan-out (which selects its
recipients by those tokens). Refresh tokens are not bound to an IdP session,
so this is every device, matching the sub-level logout_token.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FdVXRzoHDTGciZtVhbhy8y
@Mikefluff
Mikefluff merged commit d5bd427 into main Sep 27, 2026
10 checks passed
@Mikefluff
Mikefluff deleted the fix/logout-ends-rp-sessions branch September 27, 2026 22:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant