OAuth2 & OpenID Connect Deep Dive · Aula

Logout pelo Canal Frontal versus Canal Posterior

Compare as estratégias de logout pelo canal frontal e pelo canal posterior para encerrar sessões com eficácia em diferentes clientes.

Aula 3 de 411 etapas

Logout pelo Canal Frontal versus Canal Posterior é uma aula grátis de OAuth2 & OpenID Connect Deep Dive no CoddyKit. Esta é a aula 3 de 4. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de OAuth2 & OpenID Connect Deep Dive, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de OAuth2 & OpenID Connect Deep Dive inclui 4 aulas no total.

Partes desta aula ainda não foram traduzidas e aparecem em inglês.

Logging Out in OIDC

When you log out of an application, it might seem simple. You click a button, and you're out. But in systems using OpenID Connect (OIDC) or OAuth2, it's more complex.

A user often has a session with the Identity Provider (IdP) and potentially multiple client applications. A true logout means terminating all these related sessions.

The Single Logout Challenge

Single Logout (SLO) aims to log a user out of all connected applications when they initiate logout from just one. Sounds great, right?

The challenge is ensuring all clients, potentially across different domains, reliably receive and act on the logout request from the Identity Provider (IdP). This isn't always straightforward.

Front-Channel Logout Basics

Front-Channel Logout is a browser-based approach. When a user logs out, the IdP uses the user's browser to communicate with each client application.

Think of it like the IdP telling the browser, "Hey, go tell these other apps to log out too!" The browser then makes requests to the clients' logout endpoints.

How Front-Channel Logout Works

Here's how Front-Channel Logout typically works:

  • The user initiates logout (e.g., clicks "Sign Out").
  • The IdP receives the logout request.
  • The IdP redirects the user's browser to a special IdP logout page.
  • This page contains hidden <iframe> elements, each pointing to a registered client's logout URI.
  • The browser loads these iframes, causing each client to clear its local session.

Front-Channel: Good & Bad

Front-Channel Logout offers simplicity but comes with limitations:

  • Pros:
  • Relatively easy for the IdP to implement.
  • Works well for purely browser-based clients.
  • Cons:
  • Less reliable: Can be blocked by browser settings (e.g., third-party cookies, pop-up blockers).
  • Depends on the user's browser being active.
  • Doesn't work for non-browser clients (e.g., mobile apps, backend services).

Introducing Back-Channel Logout

Back-Channel Logout takes a different, more robust approach. Instead of relying on the user's browser, the Identity Provider (IdP) communicates directly with each client's backend server.

This is a server-to-server interaction, making it more reliable and suitable for a wider range of client types, especially those with server-side sessions.

How Back-Channel Logout Works

Here's the typical Back-Channel Logout sequence:

  • The user initiates logout.
  • The IdP receives the logout request and invalidates its own session.
  • The IdP then sends an HTTP POST request to each registered client's back-channel logout URI.
  • This POST request includes a signed Logout Token (a JWT).
  • Each client's server validates the Logout Token and terminates the user's local session.

Back-Channel: Good & Bad

Back-Channel Logout provides greater reliability but requires more setup:

  • Pros:
  • Highly reliable: Not dependent on browser state or user interaction.
  • Works for all client types (web, mobile, backend services).
  • Ideal for clients maintaining server-side user sessions.
  • Cons:
  • Requires clients to expose a dedicated logout endpoint.
  • More complex to implement securely (e.g., validating Logout Tokens).
  • Potential for network issues between IdP and client servers.

Choosing Your Logout Strategy

When deciding between front-channel and back-channel logout, consider your client types and reliability needs:

  • For simple, purely browser-based clients where occasional logout failures are acceptable, Front-Channel might suffice.
  • For robust applications, especially those with server-side sessions, mobile apps, or APIs, Back-Channel is generally the preferred and more secure choice.
  • Many modern systems favor back-channel for its reliability.

Quick Check: Logout Flows

Let's test your understanding of front-channel and back-channel logout characteristics.

Recap: Effective Logout

In this lesson, we explored the crucial topic of single logout in OIDC and OAuth2 systems. We learned about two primary strategies:

  • Front-Channel Logout: Browser-based, simpler, but less reliable.
  • Back-Channel Logout: Server-to-server, more robust, ideal for diverse client types and server-side sessions.

Understanding these flows helps in designing secure and user-friendly authentication systems where sessions are properly terminated across all connected services.

Grátis para começar

Aprenda OAuth2 & OpenID Connect Deep Dive com um tutor de IA — grátis

Escreva e execute código real no seu navegador, obtenha ajuda instantânea de um tutor de IA 24/7 e continue de onde parou na web ou no app.

Cursos
12
Aulas
48

Perguntas Frequentes

A aula “Logout pelo Canal Frontal versus Canal Posterior” é grátis?

Sim — o texto completo de “Logout pelo Canal Frontal versus Canal Posterior” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de OAuth2 & OpenID Connect Deep Dive, atualize para CoddyKit PRO. O curso de OAuth2 & OpenID Connect Deep Dive inclui 4 aulas no total.

O que vou aprender em “Logout pelo Canal Frontal versus Canal Posterior”?

Compare as estratégias de logout pelo canal frontal e pelo canal posterior para encerrar sessões com eficácia em diferentes clientes. Você pratica OAuth2 & OpenID Connect Deep Dive com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.

Preciso ter experiência prévia para começar OAuth2 & OpenID Connect Deep Dive?

Nenhuma experiência prévia é necessária. OAuth2 & OpenID Connect Deep Dive no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 3 de 4.

Quanto tempo leva a aula “Logout pelo Canal Frontal versus Canal Posterior”?

A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.

Posso escrever e executar código nesta aula de OAuth2 & OpenID Connect Deep Dive?

Sim. Cada aula de OAuth2 & OpenID Connect Deep Dive inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.

Todas as aulas deste curso

  1. Consentimento e Experiência do Usuário
  2. Compartilhamento de Recursos entre Origens (CORS)
  3. Logout pelo Canal Frontal versus Canal Posterior
  4. Tokens vinculados ao remetente com mTLS
← Voltar para OAuth2 & OpenID Connect Deep Dive