FeatureFuel
0

RP initiated logout does not sent id_token_hint

Source: immich-app/immich#29111 · opened by @frenzeldk
I have searched the existing issues, both open and closed, to make sure this is not a duplicate report. • Yes The bug When using OIDC with RP intiated logout as implemented in #27389, Immich does not sent id_token_hint to prove to the OIDC provider that the request is legitimate. This makes some OIDC providers, eg Keycloak[0], prompt the user if they actually want to log out. [0] The OS that Immich Server is running on Debian 13.4, Docker version 29.4.1, build 055a478 Version of Immich Server v3.0.0-rc.0 Version of Immich Mobile App 3.0.0 build.2 Platform with the issue • Server • Web • Mobile Device make and model _No response_ Your docker-compose.yml content Your .env content Reproduction steps 1. Install Immich v3.0.0-rc.0 2. Setup OIDC with keycloak 3. point end_session_endpoint at your keycloak instance with or without a valid redirect URI 4. Try logging out. Relevant log output Additional information Video demonstrating the obs…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests