SAP Knowledge Base Article - Preview

3795132 - OAuth Refresh Token Remains Valid After RP-Initiated Logout (OIDC /end_session) in SAP Customer Data Cloud

Symptom

After a user logs out via OIDC RP-Initiated Logout (/end_session), the previously issued OAuth refresh token is still valid. A subsequent /token call with grant_type=refresh_token succeeds and returns a new token pair instead of failing.

This occurs both when the user clicks Disconnect on the CDC hosted logout page, and when a Relying Party bypasses that page by calling gigya.accounts.logout (JS SDK) programmatically from an onOidc callback.


Read more...

Environment

  • SAP Customer Data Cloud
  • OpenID Connect (OIDC)
  • Relying party (RP)

Product

SAP Customer Data Cloud all versions

Keywords

IdP Single Logout, SLO, gigya , KBA , CEC-PRO-API , Core REST API & Server SDKs (JWT / PHP / Java) , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.