No state parameter in OidcLogoutActionBuilder

25 views
Skip to first unread message

Norman Lorenz

unread,
Feb 7, 2023, 10:51:38 AM2/7/23
to Pac4j users mailing list
Hello,
for logout request on OpenID Connect it is possible to send an optional state parameter. The OidcLogoutActionBuilder however is never setting this parameter. I excpected the state generator of the client to create the state value which would then be passed to the LogoutRequest. Instead "null" is set as the state. For comparison the SAML2LogoutActionBuilder is using the state genarator for its relay state, so I exptected the same mechanism for OIDC.

Is this a bug or what's the reason for not setting the state?

Kind regards,
Norman
Reply all
Reply to author
Forward
Message has been deleted
0 new messages