I can't get OpenID 1.0 Connect Logout to work. I have configured an OidcClientInitiatedLogoutSuccessHandler as shown.
I am using Spring Security 5.2, Keycloak v12, Angular v10 and Kubernetes.
Spring OAuth2Login works fine. The user hits the baseUrl, authenticates with Keycloak and is routed to the Angular code. csrf is enabled so the logout from Angular is a POST.
From the logs, Spring security invalidates the session and creates a redirectUri to Keycloak:
022-03-03 20:32:52.887 DEBUG 1 --- [nio-8080-exec-5] o.s.s.w.a.logout.LogoutFilter : Logging out [OAuth2AuthenticationToken [Principal=Name: [acme_user], Granted Authorities: [[ROLE_USER, ROLE_default-roles-acmeRealm, ROLE_offline_access, ROLE_uma_authorization, SCOPE_email, SCOPE_openid, SCOPE_profile]], User Attributes: [{at_hash=_yB9W1nuLmAQ9j_9js9XJg, sub=b8afecd5-b6f9-4016-b91f-0c206bc08801, email_verified=false, iss=http://XXX.XXX.X.XX:31131/auth/realms/acmeRealm, typ=ID, preferred_username=acme_user, nonce=MblUOo3QAYowxGbJo-t8HHLZpFphHhEWlLWkpfrwosY, aud=[acme-grid], acr=1, azp=acme-grid, auth_time=2022-03-03T20:32:01Z, exp=2022-03-03T20:37:02Z, session_state=ea33c7d3-e71f-41f9-b9af-1f947390adc3, iat=2022-03-03T20:32:02Z, jti=48944a4b-25f1-4be0-a531-f9753018f7d5}], Credentials=[PROTECTED], Authenticated=true, Details=WebAuthenticationDetails [RemoteIpAddress=ZZZ.ZZZ.ZZ.Z, SessionId=5826f702-ed97-425a-a3a4-c1098481f65b], Granted Authorities=[ROLE_USER, ROLE_default-roles-acmeRealm, ROLE_offline_access, ROLE_uma_authorization, SCOPE_email, SCOPE_openid, SCOPE_profile]]]
2022-03-03 20:32:53.008 DEBUG 1 --- [nio-8080-exec-5] o.s.s.w.a.l.SecurityContextLogoutHandler : Invalidated session 49ff75f4-0745-4f52-8263-ac35e9200b46
2022-03-03 20:32:53.011 DEBUG 1 --- [nio-8080-exec-5] o.s.s.web.DefaultRedirectStrategy : Redirecting to http://XXX.XXX.X.XX:31131/auth/realms/acmeRealm/protocol/openid-connect/logout?id_token_hint=blahblahblah
2022
From keycloak's logs, I see the session is ended for the user.
20:32:53,161 DEBUG [org.keycloak.services.util.CookieHelper] (default task-47) Could not find cookie KEYCLOAK_IDENTITY, trying KEYCLOAK_IDENTITY_LEGACY
20:32:53,161 DEBUG [org.keycloak.services.managers.AuthenticationManager] (default task-47) Could not find cookie: KEYCLOAK_IDENTITY
20:32:53,161 DEBUG [org.keycloak.services.util.CookieHelper] (default task-47) Could not find cookie KEYCLOAK_SESSION, trying KEYCLOAK_SESSION_LEGACY
20:32:53,181 DEBUG [org.keycloak.services.managers.AuthenticationManager] (default task-47) Could not find cookie: KEYCLOAK_SESSION
20:32:53,182 DEBUG [org.keycloak.services.managers.AuthenticationManager] (default task-47) Logging out: acme_user (ea33c7d3-e71f-41f9-b9af-1f947390adc3) offline: false
20:32:53,182 DEBUG [org.keycloak.services.util.CookieHelper] (default task-47) Could not find cookie KEYCLOAK_IDENTITY, trying KEYCLOAK_IDENTITY_LEGACY
20:32:53,183 DEBUG [org.keycloak.services.managers.AuthenticationManager] (default task-47) backchannel logout to: acme-grid
20:32:53,185 DEBUG [org.keycloak.services.managers.ResourceAdminManager] (default task-47) Cant logout {0}: no management url
20:32:53,186 DEBUG [org.keycloak.services.managers.AuthenticationManager] (default task-47) All clients have been logged out for user acme_user in acmeRealm realm, session ea33c7d3-e71f-41f9-b9af-1f947390adc3
20:32:53,188 DEBUG [org.keycloak.transaction.JtaTransactionWrapper] (default task-47) JtaTransactionWrapper commit
20:32:53,201 DEBUG [org.keycloak.transaction.JtaTransactionWrapper] (default task-47) JtaTransactionWrapper end
20:32:53,201 DEBUG [org.keycloak.events] (default task-47) type=LOGOUT, realmId=196bd891-7d6d-4aa9-b422-9181f69d31c1, clientId=null, userId=b8afecd5-b6f9-4016-b91f-0c206bc08801, ipAddress=ZZZ.ZZZ.ZZ.Z, authSessionParentId=ea33c7d3-e71f-41f9-b9af-1f947390adc3, authSessionTabId=tJAewwAZxfA
Instead of redirecting back to the baseUrl, the front end errors with a CORS violation:
Access to XMLHttpRequest at 'http://XXX.XXX.X.XX:31131/auth/realms/acmeRealm/protocol/openid-connect/logout?id_token_hint=blahblahblah&post_logout_redirect_uri=http://YYY.YYY.Y.YY:30001' (redirected from 'http://YYY.YYY.Y.YY:30001/logout') from origin 'http://YYY.YYY.Y.YY:30001' has been blocked by CORS policy: Request header field x-xsrf-token is not allowed by Access-Control-Allow-Headers in preflight response.
I updated the Angular code to use a _csrf param instead of an X-XSRF-TOKEN, but got a different CORS error:
/#/:1 Access to XMLHttpRequest at 'http://XXX.XXX.X.XX:31131/auth/realms/acmeRealm/protocol/openid-connect/logout?id_token_hint=blahblahblah&post_logout_redirect_uri=http://YYY.YYY.Y.YY:30001' (redirected from 'http://YYY.YYY.Y.YY:30001/logout?_csrf=748c7b1a-a634-4ce5-8728-c4f97d41820d') from origin 'http://YYY.YYY.Y.YY:30001' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.
Keycloak is configured to allow web origins of "*' right now. I am wondering if these CORS errors are spurious - since login redirects work, it's unclear to me why logout redirects would cause these CORS violations.
If I add an antMatcher to the logout config to turn off csrf for "/logout" and then call logout from Angular with a GET, then the CORS violations disapper and logout works:
http.logout(logout -> logout.logoutSuccessHandler(_oidcLogoutSuccessHandler())
.logoutRequestMatcher(new AntPathRequestMatcher("/logout")));
Thanks for reading..