FOUR-16704: Session Token Not Invalidated on Logout by danloa · Pull Request #7396 · ProcessMaker/processmaker
Issue & Reproduction Steps
The problem is described in the next video:
oauth_session_left_opened-2024-09-19_09.44.51.mp4
https://drive.google.com/file/d/1ZrFNuWyK-gioGwM9XXtV9dixT398KWks/view
Solution
- As part of the logout, the Laravel cookie is removed, so it can't be used again.
Related Tickets & Packages
Code Review Checklist
- I have pulled this code locally and tested it on my instance, along with any associated packages.
- This code adheres to ProcessMaker Coding Guidelines.
- This code includes a unit test or an E2E test that tests its functionality, or is covered by an existing test.
- This solution fixes the bug reported in the original ticket.
- This solution does not alter the expected output of a component in a way that would break existing Processes.
- This solution does not implement any breaking changes that would invalidate documentation or cause existing Processes to fail.
- This solution has been tested with enterprise packages that rely on its functionality and does not introduce bugs in those packages.
- This code does not duplicate functionality that already exists in the framework or in ProcessMaker.
- This ticket conforms to the PRD associated with this part of ProcessMaker.
ci:next