Use case: I am implementing a SSO solution for a WordPress site where the user is first authenticated on site A (non-WordPress). On successful authentication, the user is auto-loggedin to WP site by invoking a custom REST interface written by me. While user stays logged in to site A, the user is permitted to click links on site A which redirect to pages on the WP site. When user logs out of site A, I need to end the WP session as well such that any further attempt to view pages on that site will be disallowed and the user redirected back to the login screen on site A.
I have written a WP plugin which implements 3 REST interfaces:
- To register a user on the WP site
- To auto login the user on the WP site
- To logout the user on the WP site
The first two work fine. I cannot get the last to work and that is the focus of this question.
I am aware that there are various plugin solutions out there that purport to support various SSO solutions but for one reason or other have not quite worked out. I am not looking for any suggestions on plugins that I could use.
To log the user out I have written the following PHP snippet:
function logout_user($request) {
header("Access-Control-Allow-Origin: *");
wp_logout();
}
add_action('rest_api_init', function() {
register_rest_route('mycompany/v1', '/logoutuser', array(
'methods' => 'GET, OPTIONS',
'callback' => 'logout_user'));
});
I have verified that this interface is indeed being invoked, but the user is not logged out, i.e, while the browser is still open I can successfully browse to my WP site and see that my status is logged in. Only when I close and re-open the browser is the WP session terminated. How can I get this to work without needing to close the browser first?