Skip to content

feat: add logout endpoint for Dex - #1101

Open
CasLubbers wants to merge 3 commits into
APL-2079from
APL-2119
Open

CasLubbers wants to merge 3 commits into
APL-2079from
APL-2119

Conversation

@CasLubbers

@CasLubbers CasLubbers commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Signed-off-by: Cas Lubbers <clubbers@akamai.com>
Copilot AI balanced review requested due to automatic review settings October 2, 2026 08:37
@CasLubbers
CasLubbers added this pull request to stack #1102 October 2, 2026 08:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Role-less Dex users cannot access logout, and the RPC can block indefinitely without a deadline.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity · 1 Low severity

Open (3)
What changed in this PR

Adds a Dex-aware logout endpoint that revokes user sessions while preserving client logout flow.

Changes:

  • Adds authenticated POST /v2/user/logout.
  • Integrates Dex session termination as best-effort behavior.
  • Adds client, stack, and authorization tests.
File Description
src/​otomi-stack.ts Coordinates best-effort Dex logout.
src/​otomi-stack.test.ts Tests provider-specific logout behavior.
src/​openapi/​user.yaml Defines logout authorization schema.
src/​openapi/​api.yaml Documents and registers the endpoint.
src/​clients/​dexClient.ts Wraps the Dex termination RPC.
src/​clients/​dexClient.test.ts Tests the RPC wrapper.
src/​api/​v2/​user/​logout.ts Implements the HTTP handler.
src/​api-v2.authz.test.ts Tests endpoint authorization.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/openapi/api.yaml
operationId: logout
x-eov-operation-handler: v2/user/logout
description: Log out the current session. Revokes the user's Dex SSO session (when AUTH_PROVIDER is dex), in addition to the client's existing oauth2-proxy sign-out flow.
x-aclSchema: UserLogout
Comment thread src/clients/dexClient.ts
export async function terminateSessionsByUser(userId: string): Promise<number> {
const dex = getDexClient()
return new Promise<number>((resolve, reject) => {
dex.terminateSessionsByUser({ userId }, (err: ServiceError | null, resp: TerminateSessionsByUserResp) => {
Comment thread src/openapi/api.yaml
post:
operationId: logout
x-eov-operation-handler: v2/user/logout
description: Log out the current session. Revokes the user's Dex SSO session (when AUTH_PROVIDER is dex), in addition to the client's existing oauth2-proxy sign-out flow.
Signed-off-by: Cas Lubbers <clubbers@akamai.com>
Copilot AI balanced review requested due to automatic review settings October 2, 2026 09:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Role-less Dex users cannot log out, the RPC can block indefinitely, and the API contract obscures all-session revocation.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity · 1 Low severity

Open (3)
Previously missed (1)

In code that hasn't changed since last review

Medium severity No-group Dex users are denied access to logout

src/​openapi/​user.yaml:127

Authenticated Dex users with no platform/team assignment cannot call this endpoint. Such users receive __no_groups__, which getUser deliberately maps to roles: [] (src/middleware/jwt.ts:27-40), while authorization only creates rules from user.roles (src/authz.ts:163-167). Therefore this ACL returns 403 and never revokes their Dex session. Add an authenticated-user authorization path/role for logout and cover the no-groups token case.

Signed-off-by: Cas Lubbers <clubbers@akamai.com>
Copilot AI balanced review requested due to automatic review settings October 2, 2026 12:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Protobuf decoding can select the wrong field, and the API documentation understates the logout scope and best-effort behavior.

Review effort: Balanced
Findings: 2 High severity · 1 Medium severity · 3 Low severity

Open (6)

Comment thread src/clients/dexClient.ts
Comment on lines +162 to +164
const reader = Reader.create(Buffer.from(sub, 'base64'))
reader.uint32()
return reader.string()
Comment thread src/openapi/api.yaml
post:
operationId: logout
x-eov-operation-handler: v2/user/logout
description: Log out the current session. Revokes the user's Dex SSO session (when AUTH_PROVIDER is dex), in addition to the client's existing oauth2-proxy sign-out flow.
Comment thread src/openapi/user.yaml
type: object

UserLogout:
description: Permission to log out the current session. Not a CRUD resource; gates POST /v2/user/logout only.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants