potiuk opened a new pull request, #73788:
URL: https://github.com/apache/airflow/pull/73788

   When the auth manager supplies an external logout URL (FAB, Keycloak), 
`/auth/logout` revoked the token and redirected without deleting the `_token` 
cookie, so the revocation was the only thing ending the local session. 
`revoke_token` also caught every failure — including a failure to record the 
revocation — and logged it as a warning, so a revocation that did not happen 
looked the same as one that did.
   
   - The `_token` cookie is now deleted on every logout path, including the 
redirect to an external logout URL. Neither the FAB nor the Keycloak logout 
route reads it (Keycloak uses the separate ID-token cookie).
   - `revoke_token` separates a token that does not validate (already unusable, 
logged as a warning, as before) from a valid token whose revocation cannot be 
recorded, which stays usable until it expires and is now logged as an error.
   
   The new route tests stub the refresh middleware so that only the logout 
route can clear the cookie.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to