fix: Keycloak Authentication logout error with keycloak 18 or newer #5513
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
As described in #5213 trying to log-out when using the keycloak authentication strategy and
Logout from Keycloak on Logout
enabled you will currently receive anInvalid parameter: redirect_uri
error in keycloak, making logout essentially useless.As described in the discussion linked above and in https://www.keycloak.org/docs/latest/upgrading/index.html#openid-connect-logout the ideal solution would be to use an
id_token_hint
together withpost_logout_redirect_uri
in the logout request to achieve a seamless logout.I was however not sure how to get that ID Token in the logout function, so I went with the second option to restore logout functionality.
This temporarly adds an additional step for the user having to seperately click on "Logout" in keycloak and doesn't redirect the user back to the wiki, which isn't ideal, but IMO better than having no logout at all.