-
Notifications
You must be signed in to change notification settings - Fork 82
Expand file tree
/
Copy pathlogout.php
More file actions
68 lines (59 loc) · 2.74 KB
/
Copy pathlogout.php
File metadata and controls
68 lines (59 loc) · 2.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
<?php
// This file is part of Moodle - http://moodle.org/
//
// Moodle is free software: you can redistribute it and/or modify
// it under the terms of the GNU General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
//
// Moodle is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU General Public License for more details.
//
// You should have received a copy of the GNU General Public License
// along with Moodle. If not, see <http://www.gnu.org/licenses/>.
/**
* Single Sign Out end point.
*
* @package auth_oidc
* @author Lai Wei <lai.wei@enovation.ie>
* @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
* @copyright (C) 2014 onwards Microsoft, Inc. (http://microsoft.com/)
*/
use core\context\system;
use core\session\manager;
// phpcs:ignore moodle.Files.RequireLogin.Missing
require_once(__DIR__ . '/../../config.php');
$PAGE->set_url('/auth/oidc/logout.php');
$PAGE->set_context(system::instance());
$sid = optional_param('sid', '', PARAM_TEXT);
$iss = optional_param('iss', '', PARAM_TEXT);
if ($sid) {
// This request is made by the IdP directly (e.g. via a hidden iframe), so it will not carry the
// MoodleSession cookie of the user(s) being logged out, and there is no way to authenticate it.
// Do not call auth plugin logout hooks here: this is an unauthenticated endpoint, so anyone could
// trigger them merely by supplying a known sid.
$conditions = ['sid' => $sid];
if ($iss) {
// When the IdP includes iss, use it as an extra check that the mapping was created for this
// issuer, so a sid alone (without also knowing the issuer it was created for) cannot be used to
// force a logout. Not all IdPs include iss on front-channel logout requests (e.g. Azure AD
// currently does not), so this is applied only when present rather than required.
$conditions['iss'] = $iss;
}
$authoidcsidrecords = $DB->get_records('auth_oidc_sid', $conditions);
if ($authoidcsidrecords) {
// The same IdP sid can be mapped to more than one Moodle session (e.g. logins from different
// browsers/devices during the same IdP session), so destroy every session mapped to this sid.
$matchedids = [];
foreach ($authoidcsidrecords as $authoidcsidrecord) {
if (!empty($authoidcsidrecord->sessionid)) {
manager::destroy($authoidcsidrecord->sessionid);
}
$matchedids[] = $authoidcsidrecord->id;
}
$DB->delete_records_list('auth_oidc_sid', 'id', $matchedids);
}
}
die();