Details
-
New Feature
-
Resolution: Unresolved
-
Minor
-
None
-
2.26.0
-
None
-
- XWiki 17.10.12 (LTS), Docker image `xwiki:lts-postgres-tomcat`, PostgreSQL 17
- `org.xwiki.contrib.oidc:oidc-authenticator` 2.26.0. Not tested on 2.27.0, but the code path is unchanged on `master` (see below), so the behaviour should be the same there.
- Provider: Microsoft Entra ID
- Configuration object `XWiki.OIDC.ClientConfigurationClass` named `EntraID` on page `XWiki.OIDC.EntraID`- XWiki 17.10.12 (LTS), Docker image `xwiki:lts-postgres-tomcat`, PostgreSQL 17 - `org.xwiki.contrib.oidc:oidc-authenticator` 2.26.0. Not tested on 2.27.0, but the code path is unchanged on `master` (see below), so the behaviour should be the same there. - Provider: Microsoft Entra ID - Configuration object `XWiki.OIDC.ClientConfigurationClass` named `EntraID` on page `XWiki.OIDC.EntraID`
-
Unknown
-
Description
Expected
With logoutMechanism set to NONE, logging out of XWiki should end the local session only and must not call the provider's end-session endpoint.
Actual
The provider logout endpoint is still called on every logout.
| Time | Event |
|---|---|
| 12:25:00 | logoutMechanism=NONE saved (modification date of XWiki.OIDC.EntraID) |
| 12:25:16 | Request to https://login.microsoftonline.com/<tenant>/oauth2/v2.0/logout |
| 12:31:56 | Request to https://login.microsoftonline.com/<tenant>/oauth2/v2.0/logout |
| ~12:55 | logoutEndpoint set to a local URL |
| 13:10 | Logout and login again — no further request to the provider |
Counted in the log with grep -c "oauth2/v2.0/logout" /usr/local/xwiki/data/logs/xwiki.log: 6 before the change to logoutEndpoint, still 6 afterwards.
Reproducible only with an OIDC-authenticated session. A locally authenticated session never enters the OIDC logout path.
Cause: the value is never read
The property is defined and exposed, but nothing consumes it. Searching all 31 Java files of the authenticator module on master (checked 2026-09-28) yields exactly two occurrences, both in oidc-authenticator/src/main/java/org/xwiki/contrib/oidc/auth/internal/OIDCClientConfiguration.java:
public static final String PROP_LOGOUT_MECHANISM = "oidc.logoutMechanism";
…
case PROP_LOGOUT_MECHANISM:
returnValue = clientConfiguration.getLogoutMechanism();
break;
There is no code path that reads the resulting value to decide whether the provider's end-session endpoint is called. The same holds for the 2.26.0 artifacts, where the behaviour was observed.
Suggested fix
Either honour the setting in the logout path, or remove the property and its documentation so it stops promising behaviour that does not exist.
Not a duplicate of
OIDC-235 (fixed in 2.18.0): the opposite symptom — logout did not reach the provider because of an IllegalStateException. Here the provider is called although the configuration says it should not be.
OIDC-239: asks for a new option to force a provider logout when oidc.groups.allowed denies access.
OIDC-164: about propagating a logout that starts on the provider side.
OIDC-244: about clearing the client configuration cookie on logout.
Workaround
Setting logoutEndpoint to a local URL overrides the value taken from discovery and stops the call to the provider. Verified: no further requests to the provider logout endpoint after the change.