Session not cleared if user uses Back after logout
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- react, typescript
调研方向
首先,在使用 auth0-react v2.2.1 和 React 17.0.2 的 Chrome 中复现登录、注销和浏览器后退序列,并比较正常使用、打开开发者工具时的使用情况以及 auth0-react sample app。跟踪报告中显示的 Auth0Provider 配置和导航 callback;完成的标准是注销后按下 Back 无法恢复已认证的应用状态,并且刷新行为仍然正确。
由索引模型根据 Issue 内容生成。
描述
Checklist
- The issue can be reproduced in the auth0-react sample app (or N/A).
- I have looked into the Readme, Examples, and FAQ and have not found a suitable solution or answer.
- I have looked into the API documentation and have not found a suitable solution or answer.
- I have searched the issues and have not found a suitable solution or answer.
- I have searched the Auth0 Community forums and have not found a suitable solution or answer.
- I agree to the terms within the Auth0 Code of Conduct.
Description
After calling logout the user is redirect back to our login page, but if they go back with their browser they can get back into the application and perform authenticated actions. Calling refresh at any time throws them out of the application, and the auth0 logs show a successful logout.
To add more mystery to this, it does not happen consistently. For example, if the developer tools are open in the browser, the problem goes away and going back throws the user onto the login screen.
Reproduction
- login
- logout
- press back
- find yourself logged in again.
It seems to be mitigated by having the developer tools open, but is pretty much consistent in normal use. Also unable to replicate it on a localhost dev build.
Additional context
This is our auth provider
const onRedirectCallback = (appState?: AppState) => {
navigate(appState?.returnTo || window.location.pathname);
};
...
<Auth0Provider
domain={config.auth0.domain}
clientId={config.auth0.clientId}
authorizationParams={{
redirect_uri: window.location.origin,
audience: config.auth0.audience,
}}
onRedirectCallback={onRedirectCallback}
useRefreshTokens
cacheLocation={config.auth0.cacheLocation} // undefined expect for e2e tests
>
auth0-react version
v2.2.1
React version
17.0.2
Which browsers have you tested in?
Chrome
- 主要语言
- TypeScript
- 星标
- 990
- 派生
- 294
- 平均合并
- 1 天 7 小时
- 30 天内合并 PR
- 31
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
auth0/auth0-react 的其他 Issue
-
Users getting logged out with "Unsuccessful Refresh Token exchange, reused refresh token detected"未关闭bug
难度 4/5 3-5 天 新手友好度 38/100
auth0/auth0-react#929 · 16 条评论 · 1 个 reaction ·
维护者通常 1 天内回复
查看 auth0/auth0-react 的全部 Issue
相似的 Issue
-
triage
难度 1/5 1 小时以内 新手友好度 90/100
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 68/100
mermaid-js/mermaid-live-editor#2053 ·
维护者通常 1 天内回复
-
factory
难度 2/5 1-3 小时 新手友好度 82/100
jessepollak/home#1455 ·
维护者通常 1 天内回复
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
难度 1/5 1 小时以内 新手友好度 95/100
lingdojo/kana-dojo#31227 · 1 条评论 · 5 个 reaction ·
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 92/100
appandflow/stim#1838 ·
维护者通常 1 天内回复