Session not cleared if user uses Back after logout
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 35/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Stack tecnologico
- react, typescript
- Ambito
- authentication, frontend
Direzione di ricerca
Inizia riproducendo la sequenza di accesso, disconnessione e ritorno indietro del browser in Chrome con auth0-react v2.2.1 e React 17.0.2, confrontando l’uso normale con gli strumenti per sviluppatori aperti e con l’auth0-react sample app. Traccia la configurazione di Auth0Provider e il callback di navigazione mostrati nel report; il lavoro è completato quando premere Back dopo la disconnessione non può ripristinare uno stato autenticato dell’applicazione e il comportamento dell’aggiornamento rimane corretto.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Checklist
- The issue can be reproduced in the auth0-react sample app (or N/A).
- I have looked into the Readme, Examples, and FAQ and have not found a suitable solution or answer.
- I have looked into the API documentation and have not found a suitable solution or answer.
- I have searched the issues and have not found a suitable solution or answer.
- I have searched the Auth0 Community forums and have not found a suitable solution or answer.
- I agree to the terms within the Auth0 Code of Conduct.
Description
After calling logout the user is redirect back to our login page, but if they go back with their browser they can get back into the application and perform authenticated actions. Calling refresh at any time throws them out of the application, and the auth0 logs show a successful logout.
To add more mystery to this, it does not happen consistently. For example, if the developer tools are open in the browser, the problem goes away and going back throws the user onto the login screen.
Reproduction
- login
- logout
- press back
- find yourself logged in again.
It seems to be mitigated by having the developer tools open, but is pretty much consistent in normal use. Also unable to replicate it on a localhost dev build.
Additional context
This is our auth provider
const onRedirectCallback = (appState?: AppState) => {
navigate(appState?.returnTo || window.location.pathname);
};
...
<Auth0Provider
domain={config.auth0.domain}
clientId={config.auth0.clientId}
authorizationParams={{
redirect_uri: window.location.origin,
audience: config.auth0.audience,
}}
onRedirectCallback={onRedirectCallback}
useRefreshTokens
cacheLocation={config.auth0.cacheLocation} // undefined expect for e2e tests
>
auth0-react version
v2.2.1
React version
17.0.2
Which browsers have you tested in?
Chrome
- Lingua principale
- TypeScript
- Stelle
- 990
- Fork
- 294
- Merge medio
- 1g 7h
- PR unite (30g)
- 31
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di auth0/auth0-react
-
Users getting logged out with "Unsuccessful Refresh Token exchange, reused refresh token detected"Apertabug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
auth0/auth0-react#929 · 16 commenti · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di auth0/auth0-react
Issue simili
-
Difficoltà 1/5 1-3 ore Idoneità per principianti 88/100
supabase/agent-skills#611 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 68/100
polka-codes/test#345 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 1-3 ore Idoneità per principianti 92/100
GoogleChromeLabs/project-sesame#217 ·
I maintainer di solito rispondono entro 12 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
solana-foundation/solana-com#2202 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100