Skip to content

Add Logout Action #4471

@rucciva

Description

@rucciva

Preflight checklist

Ory Network Project

No response

Describe your problem

Currently, converting session to jwt is supported. But as everyone knows due to the stateless nature of jwt, session revocation before the jwt expire might not possible to be enforced, thus making it less secure.

Describe your ideal solution

It is possible for the revocation be handled by the validator of the jwt. For example krakend api gateway has a way to track jwt that has been revoked using their bloom filter . This scenario can be supported by adding logout action so that the revoked session is notified to outside system

Workarounds or alternatives

not using jwt or periodically check the jwt with kratos

Version

1.3.1

Additional Context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    featNew feature or request.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions