Add CSRF protection for /user/logout

Created on 25 February 2025, 17 days ago

Problem/Motivation

The module overrides the /user/logout route. Due to this override, the CSRF protection introduced in Drupal 10.3 was lost.

Proposed resolution

Add _csrf_token: 'TRUE' to the openid_connect.logout route.

πŸ› Bug report
Status

Active

Version

3.0

Component

Code

Created by

πŸ‡·πŸ‡΄Romania aalin

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024