spring-projects / spring-projects/spring-session
Documentation for RP Initiated Logout, and Index Session Deletion from Redis, when session naturally expires
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 1.9k
- Forks
- 1.2k
- Avg merge
- 4h 27m
- Merged PRs (30d)
- 55
Description
Expected Behavior
My Spring BFF sort of almost works (I'm now in month 3 of trying to create a robust login page).
Explicit Logout
When I explicity logout, the following function gets called, and so the session is deleted from (i) namespace > sessions, (ii) namespace > sessions > expires, (iii) namespace > sessions > session id > idx, (iv) and namespace > sessions > expiration (sorted set)
Which calls this and this:
Which calls this and this:
Which both ultimately call this:
The 4 delete methods in here get called
The following also gets called to do an RP Initiated Logout (to end the session that exists with the Auth0 Authorization server too)
- the delete BFF session, delete 2 cookies here:
- the logout from the auth server here (RP Initiated Logout):
Natural BFF session expiration
But how do I do the above, when the BFF session reaches its natural expiration time.
When this happens Redis still leaves the following
Also the Auth0 session is never logged out from (so if the person logs in again via the Spring BFF, and the Auth0 session is still valid, and it will silently login without showing the Auth0 login page)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with ReactiveRedisIndexedSessionRepository.java, especially the deletion paths linked in the issue, then compare them with SessionServerLogoutHandler.kt and OAuth2ServerLogoutSuccessHandler.kt. Determine what documentation is needed for natural BFF expiration, Redis index cleanup, and RP-Initiated Logout; done means the documented behavior and integration guidance answer these cases without relying on the external example.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, kotlin, redis, spring
- Domain
- authentication, backend, databases, documentation
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100
