Handling Logout in .NET Core (api side) with Cookie Authentication and OpenIdConnect

Viewed 416

I'm working on an API core application with .NET core 5. I protected the API with the following methods:

  • Cookie authentication
  • OpenIdConnect authentication (tokens kept in cookies, provided by an identity provider)
  • Custom session in memorycache

I use a derivated CookieAuthenticationEvents to manage sessions, overriding the methods :

  • ValidatePrincipal : I check token expiration (local, no request to identity provider) and existence of user in custom session
  • SigningIn : add in session if not exists

It works fine, and now i wonder how to handle the Log out.

I thought about the solutions, when client hits ly Logout API endpoint:

  • Calling logout to identity provider. It does invalidate token, but cookies on client side aren't deleted
  • Deleting user in my custom session. It does work, cookies still exist on client side but ValidatePrincipal will reject since no custom session for that cookie

Are those solutions "clean" ? Or is there a .NET way to tell client to delete cookies / invalidate cookie ?

Thank you

EDIT I tried it does delete cookies :)

HttpContent.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme)

There is one too ut i don't understand what it does, cookies aren't deleted and token isn't revoked on identity provider

HttpContent.SignOutAsync(OpenIdConnectDefaults.AuthenticationScheme)

0 Answers
Related