Aspnetcore: Back-channel logout support for OpenIdConnect?

Created on 1 Apr 2018  路  7Comments  路  Source: dotnet/aspnetcore

There is a default endpoint for front-channel signout: signout-oidc

Is there a plan to include a similar endpoint for back-channel signout in 2.1 release?
Spec: http://openid.net/specs/openid-connect-backchannel-1_0.html

Thank you.

affected-few area-security enhancement severity-minor

Most helpful comment

All 7 comments

No plans for this at the moment, most 2.1 feature work is already done.

The middleware couldn't implement a back channel by itself. The front channel sign out removes the user's cookie. The back channel couldn't, it would have to track sessions and invalidate them so that next time the user presents the cookie it would be rejected. Identity has features like this but it requires plugging into the cookie auth handler to enforce them.

Thank you for the response.

Awesome!
Thank you Brock!

Parking in Backlog until we see sufficient interest in this. This would be a fairly costly feature for us to implement.

@brockallen this link is dead do you have an updated link?

Was this page helpful?
0 / 5 - 0 ratings