fix(OIDC): back channel logout work for custom UI (#9487)

# Which Problems Are Solved

When using a custom / new login UI and an OIDC application with
registered BackChannelLogoutUI, no logout requests were sent to the URI
when the user signed out.
Additionally, as described in #9427, an error was logged:
`level=error msg="event of type *session.TerminateEvent doesn't
implement OriginEvent"
caller="/home/runner/work/zitadel/zitadel/internal/notification/handlers/origin.go:24"`

# How the Problems Are Solved

- Properly pass `TriggerOrigin` information to session.TerminateEvent
creation and implement `OriginEvent` interface.
- Implemented `RegisterLogout` in `CreateOIDCSessionFromAuthRequest` and
`CreateOIDCSessionFromDeviceAuth`, both used when interacting with the
OIDC v2 API.
- Both functions now receive the `BackChannelLogoutURI` of the client
from the OIDC layer.

# Additional Changes

None

# Additional Context

- closes #9427

(cherry picked from commit ed697bbd69)
This commit is contained in:
Livio Spring
2025-03-11 15:19:09 +01:00
parent 5ad33e717b
commit a47f4a30fa
8 changed files with 293 additions and 12 deletions

View File

@@ -660,7 +660,7 @@ func NewLifetimeSetEvent(
type TerminateEvent struct {
eventstore.BaseEvent `json:"-"`
TriggerOrigin string `json:"triggerOrigin,omitempty"`
TriggeredAtOrigin string `json:"triggerOrigin,omitempty"`
}
func (e *TerminateEvent) Payload() interface{} {
@@ -671,6 +671,10 @@ func (e *TerminateEvent) UniqueConstraints() []*eventstore.UniqueConstraint {
return nil
}
func (e *TerminateEvent) TriggerOrigin() string {
return e.TriggeredAtOrigin
}
func NewTerminateEvent(
ctx context.Context,
aggregate *eventstore.Aggregate,
@@ -681,6 +685,7 @@ func NewTerminateEvent(
aggregate,
TerminateType,
),
TriggeredAtOrigin: http.DomainContext(ctx).Origin(),
}
}