Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Session not cleared if user uses Back after logout

未关闭
#562 14 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
35/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
停滞
技术栈
react, typescript

调研方向

首先,在使用 auth0-react v2.2.1 和 React 17.0.2 的 Chrome 中复现登录、注销和浏览器后退序列,并比较正常使用、打开开发者工具时的使用情况以及 auth0-react sample app。跟踪报告中显示的 Auth0Provider 配置和导航 callback;完成的标准是注销后按下 Back 无法恢复已认证的应用状态,并且刷新行为仍然正确。

由索引模型根据 Issue 内容生成。

描述

enhancement
Checklist
Description

After calling logout the user is redirect back to our login page, but if they go back with their browser they can get back into the application and perform authenticated actions. Calling refresh at any time throws them out of the application, and the auth0 logs show a successful logout.

To add more mystery to this, it does not happen consistently. For example, if the developer tools are open in the browser, the problem goes away and going back throws the user onto the login screen.

Reproduction
  1. login
  2. logout
  3. press back
  4. find yourself logged in again.

It seems to be mitigated by having the developer tools open, but is pretty much consistent in normal use. Also unable to replicate it on a localhost dev build.

Additional context

This is our auth provider

  const onRedirectCallback = (appState?: AppState) => {
    navigate(appState?.returnTo || window.location.pathname);
  };
  ...
      <Auth0Provider
        domain={config.auth0.domain}
        clientId={config.auth0.clientId}
        authorizationParams={{
          redirect_uri: window.location.origin,
          audience: config.auth0.audience,
        }}
        onRedirectCallback={onRedirectCallback}
        useRefreshTokens
        cacheLocation={config.auth0.cacheLocation} // undefined expect for e2e tests
      >
auth0-react version

v2.2.1

React version

17.0.2

Which browsers have you tested in?

Chrome

主要语言
TypeScript
星标
990
派生
294
平均合并
1 天 7 小时
30 天内合并 PR
31

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

auth0/auth0-react 的其他 Issue

查看 auth0/auth0-react 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。