It wasn't really described in the original AU-02 ticket and is an extensive ticket by itself but logout is a critical feature for the oauth client.
A tenant user can decide to logout and this should invalidate/remove both the local apps oidc-provider session and also the upstream identity federation (keycloak) session. After which none of the sessions or tokens should allow resource access.
It wasn't really described in the original AU-02 ticket and is an extensive ticket by itself but logout is a critical feature for the oauth client.
A tenant user can decide to logout and this should invalidate/remove both the local apps oidc-provider session and also the upstream identity federation (keycloak) session. After which none of the sessions or tokens should allow resource access.