pomerium/internal/identity/manager
Cuong Manh Le 99142b7293
authenticate: revoke current session oauth token before sign out (#964)
authenticate: revoke current session oauth token before sign out

After #926, we don't revoke access token before sign out anymore. It
causes sign out can not work, because right after user click on sign out
button, we redirect user to idp provider authenticate page with a valid
access token, so user is logged in immediately again.

To fix it, just revoke the access token before sign out.
2020-06-23 00:55:55 +07:00
..
config.go feature/databroker: user data and session refactor project (#926) 2020-06-19 07:52:44 -06:00
data.go idp: delete sessions on refresh error, handle zero times in oauth/id tokens for refresh (#961) 2020-06-22 08:49:28 -06:00
data_test.go idp: delete sessions on refresh error, handle zero times in oauth/id tokens for refresh (#961) 2020-06-22 08:49:28 -06:00
manager.go authenticate: revoke current session oauth token before sign out (#964) 2020-06-23 00:55:55 +07:00
misc.go authenticate: revoke current session oauth token before sign out (#964) 2020-06-23 00:55:55 +07:00