fix: #718 - Clear OAuth2 authentication cookie on logout
This commit is contained in:
parent
09d933722e
commit
7425db53f6
|
|
@ -363,15 +363,25 @@ func (api *oliveTinAPI) Logout(ctx ctx.Context, req *connect.Request[apiv1.Logou
|
||||||
|
|
||||||
response := connect.NewResponse(&apiv1.LogoutResponse{})
|
response := connect.NewResponse(&apiv1.LogoutResponse{})
|
||||||
|
|
||||||
// Clear the authentication cookie by setting it to expire
|
// Clear the local authentication cookie by setting it to expire
|
||||||
cookie := &http.Cookie{
|
localCookie := &http.Cookie{
|
||||||
Name: "olivetin-sid-local",
|
Name: "olivetin-sid-local",
|
||||||
Value: "",
|
Value: "",
|
||||||
MaxAge: -1, // This tells the browser to delete the cookie
|
MaxAge: -1, // This tells the browser to delete the cookie
|
||||||
HttpOnly: true,
|
HttpOnly: true,
|
||||||
Path: "/",
|
Path: "/",
|
||||||
}
|
}
|
||||||
response.Header().Set("Set-Cookie", cookie.String())
|
response.Header().Set("Set-Cookie", localCookie.String())
|
||||||
|
|
||||||
|
// Clear the OAuth2 authentication cookie by setting it to expire
|
||||||
|
oauth2Cookie := &http.Cookie{
|
||||||
|
Name: "olivetin-sid-oauth",
|
||||||
|
Value: "",
|
||||||
|
MaxAge: -1, // This tells the browser to delete the cookie
|
||||||
|
HttpOnly: true,
|
||||||
|
Path: "/",
|
||||||
|
}
|
||||||
|
response.Header().Add("Set-Cookie", oauth2Cookie.String())
|
||||||
|
|
||||||
return response, nil
|
return response, nil
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue