altinn-studio
altinn-studio copied to clipboard
Altinn should support OIDC post_logout_redirect_uri parameter
What needs to be solved?
- The user has logged in with custom OIDC, f.ex. Feide and this app: https://udir.apps.altinn.no/udir/invitasjon-vfkl
- The user closes the app and is taken to the Altinn inbox.
- The user decides to logout.
- The user is taken to https://altinn.no/
- On that page, the user cannot select to login with OIDC (Feide).
How do you want it solved?
Altinn studio should support the post_logout_redirect_uri as described by Feide:
https://docs.feide.no/service_providers/manage/openid_connect/redir_etter_logout.html
and specified in the OpenID Connect RP-Initiated Logout 1.0 - draft 02 specification reference by the Feide documentation:
https://openid.net/specs/openid-connect-rpinitiated-1_0.html#RPLogout
When logging out, Altinn should check if the OIDC service has specified the post_logout_redirect_uri parameter and forward the user there, such that we can give the user the possibility of logging in with OIDC (Feide) again.