diff --git a/consent/manager.go b/consent/manager.go index cb685c372d..d1324c3dd6 100644 --- a/consent/manager.go +++ b/consent/manager.go @@ -52,6 +52,7 @@ type ( } LoginManager interface { GetRememberedLoginSession(ctx context.Context, id string) (*flow.LoginSession, error) + GetLoginSession(ctx context.Context, id string) (*flow.LoginSession, error) DeleteLoginSession(ctx context.Context, id string) (deletedSession *flow.LoginSession, err error) RevokeSubjectLoginSession(ctx context.Context, subject string) error ConfirmLoginSession(ctx context.Context, loginSession *flow.LoginSession) error diff --git a/consent/strategy_default.go b/consent/strategy_default.go index 768f9dd399..7b398d07db 100644 --- a/consent/strategy_default.go +++ b/consent/strategy_default.go @@ -939,7 +939,7 @@ func (s *defaultStrategy) issueLogoutVerifier(ctx context.Context, w http.Respon // We do not really want to verify if the user (from id token hint) has a session here because it doesn't really matter. // Instead, we'll check this when we're actually revoking the cookie! - session, err := s.r.LoginManager().GetRememberedLoginSession(ctx, hintSid) + session, err := s.r.LoginManager().GetLoginSession(ctx, hintSid) if errors.Is(err, x.ErrNotFound) { // Such a session does not exist - maybe it has already been revoked? In any case, we can't do much except // leaning back and redirecting back. @@ -1096,7 +1096,7 @@ func (s *defaultStrategy) HandleOpenIDConnectLogout(ctx context.Context, w http. } func (s *defaultStrategy) HandleHeadlessLogout(ctx context.Context, _ http.ResponseWriter, r *http.Request, sid string) error { - loginSession, lsErr := s.r.LoginManager().GetRememberedLoginSession(ctx, sid) + loginSession, lsErr := s.r.LoginManager().GetLoginSession(ctx, sid) if errors.Is(lsErr, x.ErrNotFound) { // This is ok (session probably already revoked), do nothing! diff --git a/persistence/sql/persister_consent.go b/persistence/sql/persister_consent.go index eec2f4557b..f51b9fc4ea 100644 --- a/persistence/sql/persister_consent.go +++ b/persistence/sql/persister_consent.go @@ -240,6 +240,20 @@ func (p *Persister) GetRememberedLoginSession(ctx context.Context, id string) (_ return &s, nil } +func (p *Persister) GetLoginSession(ctx context.Context, id string) (_ *flow.LoginSession, err error) { + ctx, span := p.r.Tracer(ctx).Tracer().Start(ctx, "persistence.sql.GetLoginSession") + defer otelx.End(span, &err) + + var s flow.LoginSession + if err := p.QueryWithNetwork(ctx).Find(&s, id); errors.Is(err, sql.ErrNoRows) { + return nil, errors.WithStack(x.ErrNotFound) + } else if err != nil { + return nil, sqlcon.HandleError(err) + } + + return &s, nil +} + // ConfirmLoginSession creates or updates the login session. The NID will be set to the network ID of the context. func (p *Persister) ConfirmLoginSession(ctx context.Context, loginSession *flow.LoginSession) (err error) { ctx, span := p.r.Tracer(ctx).Tracer().Start(ctx, "persistence.sql.ConfirmLoginSession")