Identity Server login flow stuck after Login out from External Provider

Viewed 148

I'm using Identity Server 4, version 3.1.1 and I'm getting a weird behavior after logging out from SPA clients when WS-Federation is used for the external provider. I'm currently using ADFS as external provider and it was configured following this guide: https://docs.microsoft.com/en-us/aspnet/core/security/authentication/ws-federation?view=aspnetcore-3.1

Details

When the user logs out this is what happens: Logout for the external provider is challenged -> ADFS performs the logout -> Redirection to Identity Server /Account/Logout?logoutId={logout-id} -> Identity Server redirects to /Account/Login?ReturnUrl=/Account/Logout?logoutId={logout-id} (Not encoded urls used for clarity) After that, every login redirects the user back to ADFS for login in and after login in ADFS the user ends in the URL /Account/Login?ReturnUrl=/Account/Logout?logoutId={logout-id}

Questions I have followed the requests redirections and they get me to the following code on the AccountController (QuickstartUI)

225 [HttpPost]
226 [ValidateAntiForgeryToken]
227 public async Task<IActionResult> Logout(LogoutInputModel model)
228 {
229    // build a model so the logged out page knows what to display
230    var vm = await BuildLoggedOutViewModelAsync(model.LogoutId);
231
232    if (User?.Identity.IsAuthenticated == true)
233    {
234        // delete local authentication cookie
235        await _signInManager.SignOutAsync();
236
237        // raise the logout event
238        await _events.RaiseAsync(new UserLogoutSuccessEvent(User.GetSubjectId(), User.GetDisplayName()));
239    }
240
241    // check if we need to trigger sign-out at an upstream identity provider
242    if (vm.TriggerExternalSignout)
243    {
244        // build a return URL so the upstream provider will redirect back
245        // to us after the user has logged out. this allows us to then
246        // complete our single sign-out processing.
247        string url = Url.Action("Logout", new { logoutId = vm.LogoutId });
248
249        // this triggers a redirect to the external provider for sign-out
250        return SignOut(new AuthenticationProperties { RedirectUri = url }, vm.ExternalAuthenticationScheme);
251     }
252
253    return View("LoggedOut", vm);
254 }

When the user logs out, the line 250 is reached and a logout for the external provider is invoked with a redirect url pointing to /Account/Logout?logoutId={logout-id} but when that request arrives, the user is already logged out from Identity Server, apparently because a logout was invoked on line 235 before redirecting to ADFS, therefore, the authentication is challenged while processing that redirection and the user is redirected to the /Login page.

What do I need to configure differently to process that last redirection correctly? I guess this is not a bug of Identity Server but that would mean that the logout flow wouldn't work as I expect to, how would this logout flow work then? I have posted a similar question on github but no answer so far: https://github.com/IdentityServer/IdentityServer4/issues/5204

Thanks in advance

1 Answers

GET request for Logout should allow annonymous requests.

Related