Provide & auto-configure an OidcSessionRegistry
impl for Back-Channel Logout in distributed environments
#3341
Labels
OidcSessionRegistry
impl for Back-Channel Logout in distributed environments
#3341
Expected Behavior
When using Spring Session with Spring Boot, I'd expect Back-Channel Logout to work out of the box. This would require a compatible
OidcSessionRegistry
in the application context.Current Behavior
The only
OidcSessionRegistry
provided by Spring Security isInMemoryOidcSessionRegistry
which isn't compatible with distributed OAuth2 clients.Context
I'm using
spring-cloud-gateway-mvc
configured withoauth2Login
, theTokenRelay=
filter, and Back-Channel Logout. To achieve high availability of k8s deployments, I'd like to have a minimum of two instances running in parallel. Unfortunately, for now, Back-Channel Logout won't work in this configuration.The text was updated successfully, but these errors were encountered: