批量更新
This commit is contained in:
@@ -5,6 +5,7 @@ import (
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"io"
|
||||
"net/url"
|
||||
"strings"
|
||||
|
||||
authsvc "server/services/auth"
|
||||
@@ -200,20 +201,33 @@ func (c *AuthLoginController) LogoutPage() {
|
||||
if sid != "" {
|
||||
_ = authsvc.RevokeSession(sid, models.RevokeReasonLogout)
|
||||
}
|
||||
// 走统一登出入口:吊销令牌并通知其他应用(单点登出)
|
||||
if access != "" {
|
||||
_ = authsvc.RevokeTokenPair("", access, models.RevokeReasonLogout)
|
||||
_ = authsvc.Logout(access, "")
|
||||
}
|
||||
clearSessionCookieForCtx(c.Ctx)
|
||||
|
||||
back := strings.TrimSpace(c.GetString("post_logout_redirect_uri"))
|
||||
cid := strings.TrimSpace(c.GetString("client_id"))
|
||||
if back != "" && cid != "" {
|
||||
if client, err := findClient(cid); err == nil && allowRedirect(client, back) {
|
||||
if client, err := findClient(cid); err == nil && allowLogoutRedirect(client, back) {
|
||||
c.Redirect(back, 302)
|
||||
return
|
||||
}
|
||||
// 回跳地址未登记时不要直接抛 JSON 给用户,退回登录页
|
||||
target := "/auth/login?error=" + url.QueryEscape("登出回跳地址未登记,已返回登录页")
|
||||
if cid != "" {
|
||||
target += "&client_id=" + url.QueryEscape(cid)
|
||||
}
|
||||
c.Redirect(target, 302)
|
||||
return
|
||||
}
|
||||
c.serveJSON(map[string]interface{}{"code": 200, "msg": "已登出"})
|
||||
// 浏览器直接访问(无回跳参数):跳登录页,避免页面显示裸 JSON
|
||||
target := "/auth/login"
|
||||
if cid != "" {
|
||||
target += "?client_id=" + url.QueryEscape(cid)
|
||||
}
|
||||
c.Redirect(target, 302)
|
||||
}
|
||||
|
||||
// Sessions 在线设备列表
|
||||
|
||||
Reference in New Issue
Block a user