Created on 29 November 2023, 12 months ago
Updated 14 February 2024, 9 months ago

Hello,

Is there a configuration related to the logout action after a user has logged in using the connector? Specifically, is there a way to force a re-login using the user and password of Office 365?

In the current workflow:

1. Open session: The user gets authenticated after using Microsoft OAuth.
2. Close session: The user selects the logout option (/user/logout).
3. The user is redirected to /user/login with a form containing the button "Login with Microsoft Office."
4. If the user clicks the button, they are automatically logged in. This poses a security issue because the original user might have left the browser tab open, allowing someone else to use the original user session from Office 365.

Thanks!

๐Ÿ› Bug report
Status

Fixed

Version

5.0

Component

Code

Created by

๐Ÿ‡จ๐Ÿ‡ดColombia Freddy Rodriguez Bogotรก

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024