I'm working on an API core application with .NET core 5. I protected the API with the following methods:
- Cookie authentication
- OpenIdConnect authentication (tokens kept in cookies, provided by an identity provider)
- Custom session in memorycache
I use a derivated CookieAuthenticationEvents to manage sessions, overriding the methods :
- ValidatePrincipal : I check token expiration (local, no request to identity provider) and existence of user in custom session
- SigningIn : add in session if not exists
It works fine, and now i wonder how to handle the Log out.
I thought about the solutions, when client hits ly Logout API endpoint:
- Calling logout to identity provider. It does invalidate token, but cookies on client side aren't deleted
- Deleting user in my custom session. It does work, cookies still exist on client side but ValidatePrincipal will reject since no custom session for that cookie
Are those solutions "clean" ? Or is there a .NET way to tell client to delete cookies / invalidate cookie ?
Thank you
EDIT I tried it does delete cookies :)
HttpContent.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme)
There is one too ut i don't understand what it does, cookies aren't deleted and token isn't revoked on identity provider
HttpContent.SignOutAsync(OpenIdConnectDefaults.AuthenticationScheme)