Uploaded image for project: 'Quarkus'
  1. Quarkus
  2. QUARKUS-6245

Allow setting Clear-Site-Data on OIDC logout

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done-Errata
    • Icon: Major Major
    • 3.27.0.GA
    • None
    • team/eng
    • None

      Fixes #46723.

      This simple PR allows OIDC users to choose to send one or more Clear-Site-Data directives after the logout request. Even though the PR is simple, I added a release/noteworthy-feature label to draw some attention to it since Clear-Site-Data is a rather new HTTP response header but which can be rather useful.
      Also, this PR is done as part of the threat modelling activity.

      I also did some minor, test-level only updates to fix a few logout constant names

              Unassigned Unassigned
              blafond Barry LaFond
              Martin Ocenas Martin Ocenas
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: