Uploaded image for project: 'OpenAM'
  1. OpenAM
  2. OPENAM-12553

IdP Logout is ignored when using SAML2 Auth module and trying to use a goto


    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 13.5.0, 14.1.1, 5.5.1, 6.0.0
    • Fix Version/s: 13.5.3, 6.0.0, 14.1.2, 5.5.2
    • Component/s: SAML
    • Labels:
    • Target Version/s:
    • Sprint:
      AM Sustaining Sprint 49, AM Sustaining Sprint 50
    • Story Points:
    • Needs backport:
    • Support Ticket IDs:
    • Needs QA verification:
    • Functional tests:
    • Are the reproduction steps defined?:
      Yes and I used the same an in the description


      Bug description

      When using the SAML to Authentication module in integrated Mode, OpenAM will not logout of the IdP if a goto is appended to the logout URL to trigger SP initiated Logout

      How to reproduce the issue

      1. Create a hosted SP and IdP on two OpenAM instances
      2. Created an Auth Chain using the SAML2 Authentication module as explained in the following article https://backstage.forgerock.com/knowledge/kb/article/a88521204
      3. Login to OpenAM chain with demo user using the following example.  http://host2.example.com:8080/openam/XUI/#login?service=testChain
      4. Logout normally using http://host2.example.com:8080/openam/XUI/#logout/ this will show the expected behavior
      5. Logout using a goto appended to the logout  http://host2.example.com:8080/openam/XUI/#logout?goto=[https://www.google.com|https://www.google.com/] and you will be redirected to www.google.com, but if you try to log back into the testChain you will not have to authenticate because the session has not been destroyed.
      Expected behaviour
      User should be logged out of the IdP and redirected to the goto URL
      Current behaviour
      User is redirected to the goto URL but the session on the IdP is not killed

      Work around

      No work around found



          Issue Links



              • Assignee:
                lawrence.yarham Lawrence Yarham
                abel.hoxeng Abel Hoxeng
              • Votes:
                0 Vote for this issue
                8 Start watching this issue


                • Created: