|
Important
|
Compatibility Warning: If your frontend application is updated to use this version of the SDK but your backend |
|
Tip
|
This release is otherwise compatible with Release Trains starting in the 1.8.x line. |
The frontend Auth Web SDK (@broadleaf/auth-web) now supports automatic token revocation during logout or session clearing.
Automatic Revocation: Before the token cache is cleared, the SDK will automatically iterate over the cached tokens, detect if a refresh token is present, and make a request to the /oauth2/revoke endpoint in AuthenticationServices to revoke it.
Compatibility Gating Property: To maintain backward compatibility with older versions of AuthenticationServices that do not support public clients calling the token revocation endpoint, this feature can be explicitly disabled.
Toggle Option: A new boolean option enableTokenRevocation has been added to AuthClientOptions which defaults to true. If your frontend application is updated to use the new SDK but your AuthenticationServices backend is on an older version that does not support public clients calling /oauth2/revoke, you should set enableTokenRevocation: false when instantiating the AuthClient.
To support the lookup and revocation of refresh tokens in the cache, the TokenCache interface now exposes a getEntries method:
Added getEntries?(): TokenCacheEntry[] to the TokenCache interface.
Implemented getEntries(): TokenCacheEntry[] in both InMemoryTokenCache and WebStorageTokenCache implementations.