Add path to obtain logout_token as logged in user

Created on 4 October 2018, over 5 years ago
Updated 21 August 2023, 10 months ago

You are presented with a session_token, csrf_token, and logout_token during a rest request to /user/login. You can always obtain a new copy of the csrf_token from the path /session/token. You however cannot request a new copy of the logout_token to the best of my knowledge. I propose that we make an endpoint available at /session/logouttoken where you can request a copy of this token after its initial point of creation.

This is my first time reporting an issue/creating a patch for core. Hopefully I didn't mess this process up horribly!

✨ Feature request
Status

Needs work

Version

11.0 πŸ”₯

Component
User moduleΒ  β†’

Last updated 1 minute ago

Created by

πŸ‡ΊπŸ‡ΈUnited States shawnmatthews

Live updates comments and jobs are added and updated live.
  • Needs tests

    The change is currently missing an automated test that fails when run with the original code, and succeeds when the bug has been fixed.

  • Needs change record

    A change record needs to be drafted before an issue is committed. Note: Change records used to be called change notifications.

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.69.0 2024