FOUR-16704: Session Token Not Invalidated on Logout by danloa · Pull Request #7396 · ProcessMaker/processmaker

Issue & Reproduction Steps

The problem is described in the next video:

oauth_session_left_opened-2024-09-19_09.44.51.mp4

https://drive.google.com/file/d/1ZrFNuWyK-gioGwM9XXtV9dixT398KWks/view

Solution

  • As part of the logout, the Laravel cookie is removed, so it can't be used again.

Related Tickets & Packages

Code Review Checklist

  • I have pulled this code locally and tested it on my instance, along with any associated packages.
  • This code adheres to ProcessMaker Coding Guidelines.
  • This code includes a unit test or an E2E test that tests its functionality, or is covered by an existing test.
  • This solution fixes the bug reported in the original ticket.
  • This solution does not alter the expected output of a component in a way that would break existing Processes.
  • This solution does not implement any breaking changes that would invalidate documentation or cause existing Processes to fail.
  • This solution has been tested with enterprise packages that rely on its functionality and does not introduce bugs in those packages.
  • This code does not duplicate functionality that already exists in the framework or in ProcessMaker.
  • This ticket conforms to the PRD associated with this part of ProcessMaker.

ci:next