You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It's my first time working with ouath and the oauth2-client. I couldn't find anything about user logout in the library docs.
I'm using the GenericProvider to connect using a work routes for authentication(there isn't a own provider). So in the docs of my work oauth guide they talk about a logout using a combination of:
url + token_hint + the return page. Where:
The url is the route of logout
The token_hint is the token of the user, used to eliminate the requirement of logout confirmation by the user
The return page is the page that will load in case of well succeded logout
I've tried some implementations but I didn't have success in the implementation.
The text was updated successfully, but these errors were encountered:
I don't believe OAuth itself defines any kind of logout functionality, which is why oauth2-client doesn't provide any logout mechanisms. Tokens either expire or they don't. If they do expire, OAuth provides a mechanism to refresh them, but not all providers implement token refresh.
If OAuth did define a logout, it would probably involve some manner of making a request to immediately invalidate the token so that it can't be reused on subsequent requests. Many services already provide this kind of functionality, but the user would need to log in to their account at the provider to revoke the tokens issued to other services. Most services (I've seen) do not provide token revocation through their APIs.
Hello,
It's my first time working with ouath and the oauth2-client. I couldn't find anything about user logout in the library docs.
I'm using the GenericProvider to connect using a work routes for authentication(there isn't a own provider). So in the docs of my work oauth guide they talk about a logout using a combination of:
url + token_hint + the return page. Where:
The url is the route of logout
The token_hint is the token of the user, used to eliminate the requirement of logout confirmation by the user
The return page is the page that will load in case of well succeded logout
I've tried some implementations but I didn't have success in the implementation.
The text was updated successfully, but these errors were encountered: