mirror of
				https://github.com/zitadel/zitadel.git
				synced 2025-10-25 20:38:48 +00:00 
			
		
		
		
	feat(OIDC): add back channel logout (#8837)
# Which Problems Are Solved Currently ZITADEL supports RP-initiated logout for clients. Back-channel logout ensures that user sessions are terminated across all connected applications, even if the user closes their browser or loses connectivity providing a more secure alternative for certain use cases. # How the Problems Are Solved If the feature is activated and the client used for the authentication has a back_channel_logout_uri configured, a `session_logout.back_channel` will be registered. Once a user terminates their session, a (notification) handler will send a SET (form POST) to the registered uri containing a logout_token (with the user's ID and session ID). - A new feature "back_channel_logout" is added on system and instance level - A `back_channel_logout_uri` can be managed on OIDC applications - Added a `session_logout` aggregate to register and inform about sent `back_channel` notifications - Added a `SecurityEventToken` channel and `Form`message type in the notification handlers - Added `TriggeredAtOrigin` fields to `HumanSignedOut` and `TerminateSession` events for notification handling - Exported various functions and types in the `oidc` package to be able to reuse for token signing in the back_channel notifier. - To prevent that current existing session termination events will be handled, a setup step is added to set the `current_states` for the `projections.notifications_back_channel_logout` to the current position - [x] requires https://github.com/zitadel/oidc/pull/671 # Additional Changes - Updated all OTEL dependencies to v1.29.0, since OIDC already updated some of them to that version. - Single Session Termination feature is correctly checked (fixed feature mapping) # Additional Context - closes https://github.com/zitadel/zitadel/issues/8467 - TODO: - Documentation - UI to be done: https://github.com/zitadel/zitadel/issues/8469 --------- Co-authored-by: Hidde Wieringa <hidde@hiddewieringa.nl>
This commit is contained in:
		| @@ -58,6 +58,7 @@ const ( | ||||
| 	AppOIDCConfigColumnClockSkew                = "clock_skew" | ||||
| 	AppOIDCConfigColumnAdditionalOrigins        = "additional_origins" | ||||
| 	AppOIDCConfigColumnSkipNativeAppSuccessPage = "skip_native_app_success_page" | ||||
| 	AppOIDCConfigColumnBackChannelLogoutURI     = "back_channel_logout_uri" | ||||
|  | ||||
| 	appSAMLTableSuffix             = "saml_configs" | ||||
| 	AppSAMLConfigColumnAppID       = "app_id" | ||||
| @@ -125,6 +126,7 @@ func (*appProjection) Init() *old_handler.Check { | ||||
| 			handler.NewColumn(AppOIDCConfigColumnClockSkew, handler.ColumnTypeInt64, handler.Default(0)), | ||||
| 			handler.NewColumn(AppOIDCConfigColumnAdditionalOrigins, handler.ColumnTypeTextArray, handler.Nullable()), | ||||
| 			handler.NewColumn(AppOIDCConfigColumnSkipNativeAppSuccessPage, handler.ColumnTypeBool, handler.Default(false)), | ||||
| 			handler.NewColumn(AppOIDCConfigColumnBackChannelLogoutURI, handler.ColumnTypeText, handler.Nullable()), | ||||
| 		}, | ||||
| 			handler.NewPrimaryKey(AppOIDCConfigColumnInstanceID, AppOIDCConfigColumnAppID), | ||||
| 			appOIDCTableSuffix, | ||||
| @@ -500,6 +502,7 @@ func (p *appProjection) reduceOIDCConfigAdded(event eventstore.Event) (*handler. | ||||
| 				handler.NewCol(AppOIDCConfigColumnClockSkew, e.ClockSkew), | ||||
| 				handler.NewCol(AppOIDCConfigColumnAdditionalOrigins, database.TextArray[string](e.AdditionalOrigins)), | ||||
| 				handler.NewCol(AppOIDCConfigColumnSkipNativeAppSuccessPage, e.SkipNativeAppSuccessPage), | ||||
| 				handler.NewCol(AppOIDCConfigColumnBackChannelLogoutURI, e.BackChannelLogoutURI), | ||||
| 			}, | ||||
| 			handler.WithTableSuffix(appOIDCTableSuffix), | ||||
| 		), | ||||
| @@ -522,7 +525,7 @@ func (p *appProjection) reduceOIDCConfigChanged(event eventstore.Event) (*handle | ||||
| 		return nil, zerrors.ThrowInvalidArgumentf(nil, "HANDL-GNHU1", "reduce.wrong.event.type %s", project.OIDCConfigChangedType) | ||||
| 	} | ||||
|  | ||||
| 	cols := make([]handler.Column, 0, 15) | ||||
| 	cols := make([]handler.Column, 0, 16) | ||||
| 	if e.Version != nil { | ||||
| 		cols = append(cols, handler.NewCol(AppOIDCConfigColumnVersion, *e.Version)) | ||||
| 	} | ||||
| @@ -568,6 +571,9 @@ func (p *appProjection) reduceOIDCConfigChanged(event eventstore.Event) (*handle | ||||
| 	if e.SkipNativeAppSuccessPage != nil { | ||||
| 		cols = append(cols, handler.NewCol(AppOIDCConfigColumnSkipNativeAppSuccessPage, *e.SkipNativeAppSuccessPage)) | ||||
| 	} | ||||
| 	if e.BackChannelLogoutURI != nil { | ||||
| 		cols = append(cols, handler.NewCol(AppOIDCConfigColumnBackChannelLogoutURI, *e.BackChannelLogoutURI)) | ||||
| 	} | ||||
|  | ||||
| 	if len(cols) == 0 { | ||||
| 		return handler.NewNoOpStatement(e), nil | ||||
|   | ||||
		Reference in New Issue
	
	Block a user
	 Livio Spring
					Livio Spring