Closed (fixed)
Project:
OpenID Connect / OAuth client
Version:
3.0.0-alpha6
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
25 Feb 2025 at 06:07 UTC
Updated:
12 May 2025 at 14:29 UTC
Jump to comment: Most recent
Comments
Comment #2
pfrillingThanks for the report. Working on this today.
Comment #4
pfrillingCSRF protection and tests confirming have been added to the logout route.
I think we create a follow up issue to introduce the
_csrf_confirm_form_routethat mimics theOpenIDConnectRedirectController::redirectLogout. That seemed like a bigger refactor and likely warrants a separate issue.Comment #5
jibus commentedI applied the patch.
The user/logout route now returns a 403.
This is the logical behavior, but is it the expected behavior?
Shouldn't we have the confirmation form?
Comment #6
pfrilling@jibus, Yes, I do think we need to add the confirmation form to match core's workflow, but I was planning on doing that work in a separate issue.
Comment #7
jibus commented@pfrilling You specified it, my bad.
Comment #8
pfrillingI'm marking this as RTBC from @jibus's review in #5.
Comment #10
pfrillingCode has been merged and the followup issue has been created to add the confirmation form here: https://www.drupal.org/project/openid_connect/issues/3518252
Comment #11
attheshow commentedI just wanted to post a heads up here. It looks like this change is for some reason causing a 403 error when a currently-logged-in user visits /user/logout on D11.
Comment #12
pfrillingThanks @attheshow. That is expected as the route requires a csrf token. Browsing directly to that route won't have the token, hence the 403. If you use the logout link provided by a menu and/or the login block, it should work. The followup issue #3518252: Add _csrf_confirm_form_route option for to the user/logout route will get that direct link remedied with a confirmation form.
Comment #13
attheshow commentedOK, I'll go ahead and put together a patch for our site so that we can continue to use our existing logout links on D11.
Comment #14
pfrillingThe confirmation form logic is in place here: https://www.drupal.org/project/openid_connect/issues/3518252.
@attheshow, are you able to manually test that MR and confirm if it works for your use case?
Comment #15
attheshow commentedSorry, I haven't been able to test that just yet.