feat: add OIDC back-channel logout (#1734)

Co-authored-by: Alessandro (Ale) Segala <43508+ItalyPaleAle@users.noreply.github.com>
Co-authored-by: Elias Schneider <login@eliasschneider.com>
This commit is contained in:
Alec Rubin
2026-09-23 21:34:38 +02:00
committed by GitHub
co-authored by Alessandro Segala Elias Schneider
parent 23c4825abd
commit 2075de3234
33 changed files with 1493 additions and 96 deletions
+15 -4
View File
@@ -41,16 +41,27 @@ type ScimSyncScheduler interface {
ScheduleSync(ctx context.Context)
}
// BackchannelLogoutNotifier tells OIDC clients to end their sessions for users the sync deprovisions
type BackchannelLogoutNotifier interface {
// PrepareUserNotifications resolves the notifications within the sync transaction and returns a function that delivers them, which must only be called after the transaction has committed
PrepareUserNotifications(ctx context.Context, tx *gorm.DB, userIDs []string) (func(), error)
// NotifyLostGroupAccess delivers logout tokens to group-restricted clients the given users can no longer access, and must be called after the transaction has committed
// The sync passes an empty client ID, matching on the users alone
NotifyLostGroupAccess(ctx context.Context, userIDs []string, clientID string)
}
type Dependencies struct {
DB *gorm.DB
Actors francishost.Host
HTTPClient *http.Client
FileStorage storage.FileStorage
Users UserSyncer
Groups GroupSyncer
AppConfig appconfig.AppConfigResolver
ScimSync ScimSyncScheduler
Users UserSyncer
Groups GroupSyncer
AppConfig appconfig.AppConfigResolver
ScimSync ScimSyncScheduler
BackchannelLogout BackchannelLogoutNotifier
// ScheduleDisabled keeps the recurring sync from being armed
// It's set in the test environment, where syncs are driven explicitly by the end-to-end tests