Class: Users::SessionsController

Inherits:
Devise::SessionsController
  • Object
show all
Includes:
JwtUtilities
Defined in:
app/controllers/users/sessions_controller.rb

Instance Method Summary collapse

Methods included from JwtUtilities

#jwt_valid?, #public_key

Instance Method Details

#endsessionObject



19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
# File 'app/controllers/users/sessions_controller.rb', line 19

def endsession
  headers = { 'Cache-Control' => 'no-store' }
  Rails.logger.info("endsession called with params: #{params}")
  if jwt_valid?(params[:logout_token], 'http://schemas.openid.net/event/backchannel-logout')
    payload, _header = JWT.decode(params[:logout_token], nil, false)
    user_identity = payload['sub']
    user = User.find_by(uid: user_identity)
    if user
      user.invalidate_all_sessions!
      invalidate_navbar_cache(user)
      render json: {}, status: :ok, headers:
    else
      render json: {}, status: :bad_request, headers:
    end
  else
    render json: {}, status: :bad_request, headers:
  end
end

#initiate_backchannel_logoutObject



38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
# File 'app/controllers/users/sessions_controller.rb', line 38

def initiate_backchannel_logout
Rails.logger.info "[DEBUG] INITIATE BACKCHANNEL LOGOUT - User: #{current_user&.id}, Session: #{session.id}, Refresh Token: #{session[:refresh_token]}"

redirect_to user_strongmind_omniauth_authorize_url, allow_other_host: true and return unless current_user

if session[:refresh_token].blank? && current_user&.auth_token_cache.blank?
  Rails.logger.error "[DEBUG] LOGOUT ISSUE DETECTED - User: #{current_user.id}, Session: #{session.id}, No tokens available"
end

user_token_info = fetch_user_token_info

  id_token_hint = user_token_info[:id_token]
  current_user&.invalidate_all_sessions!
  invalidate_navbar_cache
  identity_base_url = ENV['IDENTITY_BASE_URL']
  redirect_to "#{identity_base_url}/connect/endsession?id_token_hint=#{id_token_hint}", allow_other_host: true
end

#loginObject



11
12
13
# File 'app/controllers/users/sessions_controller.rb', line 11

def 
  redirect_to user_strongmind_omniauth_authorize_url, allow_other_host: true
end

#newObject



15
16
17
# File 'app/controllers/users/sessions_controller.rb', line 15

def new
  redirect_to user_strongmind_omniauth_authorize_url, allow_other_host: true
end