mirror of
https://github.com/go-gitea/gitea.git
synced 2026-07-28 09:15:18 +02:00
Fixes #38209 OAuth2-linked accounts that sign in via the password form were still redirected to the provider end_session_endpoint on logout because the redirect was keyed off account LoginType. Store the session sign-in method (password vs oauth2) and only use RP-initiated OIDC logout when this session was authenticated via OAuth2. Sessions without the new key keep the previous LoginType behavior. --------- Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
19 lines
439 B
Go
19 lines
439 B
Go
// Copyright 2025 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package session
|
|
|
|
const (
|
|
KeyUID = "uid"
|
|
|
|
KeyImpersonatorData = "impersonatorData"
|
|
|
|
KeyUserHasTwoFactorAuth = "userHasTwoFactorAuth"
|
|
|
|
// KeySignInMethod records how the current session was authenticated so logout
|
|
// can decide whether RP-initiated OIDC logout is appropriate.
|
|
KeySignInMethod = "signInMethod"
|
|
|
|
SignInMethodOAuth2 = "oauth2"
|
|
)
|