fix: terminate session possible wihtout id_token_hint
This commit is contained in:
parent
653540c27d
commit
f8fc7961b2
1 changed files with 8 additions and 1 deletions
|
@ -27,7 +27,11 @@ func EndSession(w http.ResponseWriter, r *http.Request, ender SessionEnder) {
|
||||||
RequestError(w, r, err)
|
RequestError(w, r, err)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
err = ender.Storage().TerminateSession(r.Context(), session.UserID, session.Client.GetID())
|
var clientID string
|
||||||
|
if session.Client != nil {
|
||||||
|
clientID = session.Client.GetID()
|
||||||
|
}
|
||||||
|
err = ender.Storage().TerminateSession(r.Context(), session.UserID, clientID)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
RequestError(w, r, ErrServerError("error terminating session"))
|
RequestError(w, r, ErrServerError("error terminating session"))
|
||||||
return
|
return
|
||||||
|
@ -50,6 +54,9 @@ func ParseEndSessionRequest(r *http.Request, decoder *schema.Decoder) (*oidc.End
|
||||||
|
|
||||||
func ValidateEndSessionRequest(ctx context.Context, req *oidc.EndSessionRequest, ender SessionEnder) (*EndSessionRequest, error) {
|
func ValidateEndSessionRequest(ctx context.Context, req *oidc.EndSessionRequest, ender SessionEnder) (*EndSessionRequest, error) {
|
||||||
session := new(EndSessionRequest)
|
session := new(EndSessionRequest)
|
||||||
|
if req.IdTokenHint == "" {
|
||||||
|
return session, nil
|
||||||
|
}
|
||||||
claims, err := ender.IDTokenVerifier().Verify(ctx, "", req.IdTokenHint)
|
claims, err := ender.IDTokenVerifier().Verify(ctx, "", req.IdTokenHint)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, ErrInvalidRequest("id_token_hint invalid")
|
return nil, ErrInvalidRequest("id_token_hint invalid")
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue