OpenID Connect Logout Improvement in RH-SSO 7.6 #161
-
What is the impact of RH-SSO 7.6 (Keycloak v18) on the user session logout process? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
One of the changes made in the latest To summary, there are two ways of logging out the authenticated users from the Keycloak (RH-SSO 7.6):
References: |
Beta Was this translation helpful? Give feedback.
One of the changes made in the latest
RH-SSO version 7.6 (Keycloak v18)
, to remove the negative impact on performance and security, is aroundOpenID Connect Logout
that follows theOpenID Connect RP-Initiated Logout specification
and deprecates the parameterredirect_uri
.Since many Gov teams make use of the
redirect_uri
parameter to log out the users in their applications, we applied an available patch to support the backwards compatibility option withredirect_uri
; we also want to highlight that this option will be completely deprecated in the future Keycloak releases.To summary, there are two ways of logging out the authenticated users from the Keycloak (RH-SSO 7.6):
include
id_toke…