Uploaded image for project: 'OpenId Connect'
  1. OpenId Connect
  2. OIDC-320

Allow disabling the logout on provider side

    XMLWordPrintable

Details

    • New Feature
    • Resolution: Unresolved
    • Minor
    • None
    • 2.26.0
    • Authenticator
    • None
    • Unknown

    Description

      Expected

      With logoutMechanism set to NONE, logging out of XWiki should end the local session only and must not call the provider's end-session endpoint.

      Actual

      The provider logout endpoint is still called on every logout.

      Time Event
      12:25:00 logoutMechanism=NONE saved (modification date of XWiki.OIDC.EntraID)
      12:25:16 Request to https://login.microsoftonline.com/<tenant>/oauth2/v2.0/logout
      12:31:56 Request to https://login.microsoftonline.com/<tenant>/oauth2/v2.0/logout
      ~12:55 logoutEndpoint set to a local URL
      13:10 Logout and login again — no further request to the provider

      Counted in the log with grep -c "oauth2/v2.0/logout" /usr/local/xwiki/data/logs/xwiki.log: 6 before the change to logoutEndpoint, still 6 afterwards.

      Reproducible only with an OIDC-authenticated session. A locally authenticated session never enters the OIDC logout path.

      Cause: the value is never read

      The property is defined and exposed, but nothing consumes it. Searching all 31 Java files of the authenticator module on master (checked 2026-09-28) yields exactly two occurrences, both in oidc-authenticator/src/main/java/org/xwiki/contrib/oidc/auth/internal/OIDCClientConfiguration.java:

      public static final String PROP_LOGOUT_MECHANISM = "oidc.logoutMechanism";
      …
      case PROP_LOGOUT_MECHANISM:
      returnValue = clientConfiguration.getLogoutMechanism();
      break;

      There is no code path that reads the resulting value to decide whether the provider's end-session endpoint is called. The same holds for the 2.26.0 artifacts, where the behaviour was observed.

      Suggested fix

      Either honour the setting in the logout path, or remove the property and its documentation so it stops promising behaviour that does not exist.

      Not a duplicate of

      OIDC-235 (fixed in 2.18.0): the opposite symptom — logout did not reach the provider because of an IllegalStateException. Here the provider is called although the configuration says it should not be.
      OIDC-239: asks for a new option to force a provider logout when oidc.groups.allowed denies access.
      OIDC-164: about propagating a logout that starts on the provider side.
      OIDC-244: about clearing the client configuration cookie on logout.

      Workaround

      Setting logoutEndpoint to a local URL overrides the value taken from discovery and stops the call to the provider. Verified: no further requests to the provider logout endpoint after the change.

      Attachments

        Activity

          People

            Unassigned Unassigned
            awe André Weidich
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated: