Delete cookies in Flutter oauth2_client package embedded browser

Viewed 302

I am using the oauth2_client package in Flutter to access APIs of various services like Dropbox and Microsoft Graph via Oauth2.

The package works great, but I cannot get the user to log out. I called the method to delete the stored tokens (e.g. onedriveHelper.disconnect()) after specifying the revokeURL when defining the client itself.

The problem: When the user clicks the login but after presumably logging out, the embeded browser seems to have stored the account in some sort of cookie or session, as the user is still logged in the browser. The user does not see the fields to input the credentials. Instead, the user is already logged in and now only has to confirm the connection to the app - as if he has just logged in successfully: screen to approve the app even though no credentials have been entered

How can I reset or permanently delete all cookies or states from the embedded browser which oauth2_client uses?

Thanks! Chris

1 Answers

I had a similar problem, but I am not using the oauth2_client package. If you use Flutter AppAuth package instead (Or if your package perhaps has a similar option), the AuthorizationTokenRequest object gives you an optional parameter for promptValues. If 'log in' is one of the prompts, the embedded browser will not automatically log you in. Here is how I use it in my code:

final AuthorizationTokenResponse? result =
      await appAuth.authorizeAndExchangeCode(
    AuthorizationTokenRequest(AUTH0_CLIENT_ID, AUTH0_REDIRECT_URI,
        issuer: AUTH0_ISSUER,
        scopes: <String>['openid', 'profile', 'offline_access'],
        promptValues: ['log in']),
  );

See this page for a full example using the package: https://github.com/auth0-blog/flutter-authentication

Related