Skip to content

fix(oidc-auth): delete domain-scoped session cookie on invalidation - #2175

Open
ChethankumarGS wants to merge 3 commits into
honojs:mainfrom
ChethankumarGS:patch-1
Open

ChethankumarGS wants to merge 3 commits into
honojs:mainfrom
ChethankumarGS:patch-1

Conversation

@ChethankumarGS

Copy link
Copy Markdown

Follow-up to #1490. That fix covered revokeSession(), but the other session-invalidation paths still call deleteCookie() without the configured OIDC_COOKIE_DOMAIN. A cookie's identity is its (name, domain, path) triple, so the domain-scoped session cookie - the one updateAuth() actually sets - survives invalidation and the session stays alive.

Changes:

  • Add a deleteSessionCookie() helper (same delete-both pattern as revokeSession()) and use it in getAuth() (invalid JWT, empty refresh token, rejected refresh grant), the oidcAuthMiddleware() catch block, and revokeSession() itself
  • Delete the state / nonce / code_verifier / continue flow cookies in processOAuthCallback() with the domain they were set with
  • Include the configured domain in the session-cookie re-set after next(), so it matches updateAuth() instead of creating a divergent host-only cookie

Tests: three regression tests covering invalidation with OIDC_COOKIE_DOMAIN set (invalid JWT, rejected refresh grant, renewal without a host-only duplicate). All three fail on main and pass with the fix; the full @hono/oidc-auth suite passes (45 tests).

Fixes #2174

@changeset-bot

changeset-bot Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9338711

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@hono/oidc-auth Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Ensure the domain-scoped session cookie is deleted on all invalidation paths, not just in revokeSession(). This change addresses issues with cookie identity and ensures consistent behavior across invalidation scenarios.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

oidc-auth: session cookie is not deleted on invalidation when OIDC_COOKIE_DOMAIN is set

1 participant