Fix: Username schemas and zitadel anonymization - #276
Closed
carlosplanchon wants to merge 7 commits into
Closed
Conversation
Signed-off-by: Carlos Andrés Planchón Prestes <carlosandresplanchonprestes@gmail.com>
The OAuth callback now stashes the provider's id_token in the session
metadata (server-side only, and only for providers with a registered
end_session endpoint). /logout reads it before revoking the session
and, for those OIDC sessions, additionally returns a logout_url built
from the end_session endpoint plus id_token_hint and
post_logout_redirect_uri, so the client can navigate there and
terminate the IdP's own SSO session too (otherwise the next "login
with Zitadel" silently re-enters without credentials).
The local logout always happens regardless; navigating to logout_url
is the client's opt-in. Password and Google sessions keep the exact
old response shape. Wired for Zitadel via oauth_end_session_endpoints
in oauth.py; any future OIDC provider is a one-line entry. Requires
registering {OAUTH_REDIRECT_BASE_URL}/ as a Post Logout URI in the
IdP app (documented in .env.example).
Covered by test_oidc_logout_returns_end_session_url: a full callback
then logout round-trip asserting the URL carries the stashed
id_token_hint.
Signed-off-by: Carlos Andrés Planchón Prestes <carlosandresplanchonprestes@gmail.com>
…I-boilerplate into feat/zitadel-oauth
Signed-off-by: Carlos Andrés Planchón Prestes <carlosandresplanchonprestes@gmail.com>
…nonymization Fix: Username schemas and zitadel anonymization
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Contributed by @nicolasgutierrezdev
carlosplanchon#2