OpenID Connect signout flow redirecting to wrong Connect client

Viewed 17

My signout code for an application authenticated via a OpenID Connect client:

public async Task OnGetAsync()
        {
            await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme);
            var prop = new AuthenticationProperties
            {
                RedirectUri = "/"
            };
            await HttpContext.SignOutAsync("oidc", prop);
        }

Signout flow is commenced, and it is redirected to a OIDC login page, but not for the correct client (redirected to the "Home"-Connect client login page, instead of my application Connect client login page). Is there a way to apply clientID information to the RedirectUri or could this be handled in another way?

The code for the configuration of authentication:

services.AddAuthentication(opt =>
            {
                opt.DefaultAuthenticateScheme = CookieAuthenticationDefaults.AuthenticationScheme;
                opt.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
                opt.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme;
            }).AddCookie().AddOpenIdConnect("oidc", options =>
            {
                options.Authority = "CONNECT AUTHORITY URL";
                options.ClientId = configuration.GetSection("AuthorizationStrings")["ClientId"];
                options.ClientSecret = configuration.GetSection("AuthorizationStrings")["ClientSecret"];
                options.ResponseType = "code";
                options.SaveTokens = true;
                options.GetClaimsFromUserInfoEndpoint = true;
                options.UseTokenLifetime = false;
                options.Scope.Add("openid");
                options.Scope.Add("profile");
                options.TokenValidationParameters = new TokenValidationParameters { NameClaimType = "name" };

                options.Events = new OpenIdConnectEvents
                {
                    OnAccessDenied = context =>
                    {
                        context.HandleResponse();
                        context.Response.Redirect("/");
                        return Task.CompletedTask;
                    }
                };
            });

Code for configure HTTP request pipeline:

public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
        {
            if (env.IsDevelopment())
            {
                app.UseDeveloperExceptionPage();
            }
            else
            {
                app.UseExceptionHandler("/Error");
                // The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts.
                app.UseHsts();
            }

            app.UseHttpsRedirection();
            app.UseStaticFiles();
            app.UseRouting();
            app.UseAuthentication();
            app.UseAuthorization();

            app.UseEndpoints(endpoints =>
            {
                endpoints.MapBlazorHub();
                endpoints.MapFallbackToPage("/_Host");
            });
        }

0 Answers
Related