跳到主内容

RP 发起的登出

RP-initiated logout lets a relying party (RP), which is your client application, sign the user out of Casdoor and then send the browser back to the application. Casdoor implements OpenID Connect RP-Initiated Logout 1.0. OpenID Connect (OIDC) client libraries call this endpoint as the end-session endpoint.

To end every session of a user in the organization at once, use single sign-out instead.

端点​

GET  /api/logout
POST /api/logout

Parameters​

参数必需映射的工具
id_token_hint推荐Casdoor 之前签发给用户的 ID 令牌(id_token)。提供时,Casdoor 用它来定位并使对应的令牌 / 会话过期。
post_logout_redirect_uri可选登出后浏览器跳转到哪里。必须登记在应用的 Redirect URLs 列表中,否则请求会被拒绝。
client_id可选应用的客户端 ID。在没有 id_token_hint、且无法从当前会话确定应用时,用来定位应用。
州/省可选一个不透明的值,会作为 state 查询参数追加到 post_logout_redirect_uri 后返回。
信息

The OIDC specification recommends id_token_hint but doesn't require it. Casdoor accepts requests without it and then signs out the current browser session. Some clients, such as Gitea, send only post_logout_redirect_uri, optionally with client_id.

Behavior​

What Casdoor does depends on whether the request contains id_token_hint.

With an ID token hint​

  1. Casdoor expires the token that id_token_hint identifies.
  2. Casdoor clears the current browser session and sends a back-channel logout notification to the other applications.
  3. If post_logout_redirect_uri is present and valid for the application, Casdoor redirects the browser to it and appends state if the request contains it. Otherwise, Casdoor returns HTTP 200.

Without an ID token hint​

  1. If the browser has no active session, the user is already signed out. Casdoor returns HTTP 200 and does nothing else.
  2. Otherwise, Casdoor signs out the current session. It takes the application from the session and falls back to the application that client_id identifies.
  3. Casdoor clears the session and its token and sends a back-channel logout notification.
  4. If post_logout_redirect_uri is present and valid for the application, Casdoor redirects the browser to it and appends state if the request contains it.
  5. If the request has no post_logout_redirect_uri, Casdoor returns HTTP 200. The response includes the home page URL of the application if one is set, except for the built-in application.

Redirect URL validation​

Casdoor always checks post_logout_redirect_uri against the Redirect URLs of the application. If the URL isn't in that list, or if Casdoor can't determine the application, Casdoor rejects the request with an error and doesn't redirect. This prevents open redirects.

Add your post-logout URL to the Redirect URLs of the application.

示例​

Sign out with the ID token and return to the application:

GET /api/logout?id_token_hint=<ID_TOKEN>&post_logout_redirect_uri=https://myapp.example.com/logged-out&state=xyz

Sign out the current session without an ID token, and identify the application by its client ID:

GET /api/logout?client_id=<CLIENT_ID>&post_logout_redirect_uri=https://myapp.example.com/logged-out

另请参阅​