Wordpress apps OIDC: logout/login security issue
-
Suddenly on one of my Cloudrons all Wordpress app got update with the OIDC login method (much sooner than expected!).
However in my opinion (mentioned before) there is still a security issue with your implementation of OIDC: you can log out of Wordpress (or espoCRM) but pressing "Login with Cloudron" right after (or after leaving your computer and someone else is using it) you are immediately logged in again.
For computers that are shared like in a non-profit organization with volunteers this is really an issue!
-
There must be a kind of functionality for this: in the Wordpress OpenID Connect Client plugin there is an option:
End Session Endpoint URL
Identify provider logout endpoint.
Example: https://example.com/oauth2/logoutBut not filled in, so there must be a way to really logout?
-
I can see the problem for shared PCs but the right approach for shared PCs is to enable some sort of kiosk mode. Or elaborate use of anonymous mode.
You can try this with wix.com for example:
-
-
This post is deleted!
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login