Simplify ProfileDropdown logout logic by redirecting to /logout and update nginx.conf to restrict /logout to GET and POST methods only.
This commit is contained in:
@@ -40,6 +40,8 @@ http {
|
||||
|
||||
# Full logout: clears local session and redirects to Keycloak logout
|
||||
location = /logout {
|
||||
limit_except GET POST { deny all; } # allow both GET and POST
|
||||
|
||||
access_by_lua_block {
|
||||
local session = require("resty.session").start()
|
||||
session:destroy()
|
||||
|
||||
Reference in New Issue
Block a user