Broadleaf Microservices
  • v1.0.0-latest-prod

Auth JS SDK Release Notes for 1.6.8

Important

Compatibility Warning: If your frontend application is updated to use this version of the SDK but your backend AuthenticationServices is on an older version that does not support public clients calling /oauth2/revoke, browser console errors will appear during logout or session clearing. To prevent these console errors, you should explicitly set enableTokenRevocation: false when instantiating the AuthClient.

Tip

This release is otherwise compatible with Release Trains starting in the 1.8.x line.

Enhancements & Notable Features

Frontend Token Revocation

The frontend Auth Web SDK (@broadleaf/auth-web) now supports automatic token revocation during logout or session clearing.

  • Automatic Revocation: Before the token cache is cleared, the SDK will automatically iterate over the cached tokens, detect if a refresh token is present, and make a request to the /oauth2/revoke endpoint in AuthenticationServices to revoke it.

  • Compatibility Gating Property: To maintain backward compatibility with older versions of AuthenticationServices that do not support public clients calling the token revocation endpoint, this feature can be explicitly disabled.

  • Toggle Option: A new boolean option enableTokenRevocation has been added to AuthClientOptions which defaults to true. If your frontend application is updated to use the new SDK but your AuthenticationServices backend is on an older version that does not support public clients calling /oauth2/revoke, you should set enableTokenRevocation: false when instantiating the AuthClient.

Token Cache API Updates

To support the lookup and revocation of refresh tokens in the cache, the TokenCache interface now exposes a getEntries method:

  • Added getEntries?(): TokenCacheEntry[] to the TokenCache interface.

  • Implemented getEntries(): TokenCacheEntry[] in both InMemoryTokenCache and WebStorageTokenCache implementations.

Bug Fixes

  • Fixed race-condition when using iframe for silent-callback authorization where some token responses were handled out of order