hsiegeln
6e4977ea3b
docs(plan): logout hardening implementation plan
...
Tracks the work to (a) fix the silently-inert token-revocation lookup in
JwtAuthenticationFilter, (b) add POST /api/v1/auth/logout that bumps
users.token_revoked_before, and (c) replace the broken cross-origin
fetch logout in the SPA with proper RP-Initiated Logout (top-level
redirect) plus a signed-out splash and prompt=login defence.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-04-27 09:01:52 +02:00
..
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-03-29 18:15:10 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-04 15:45:49 +02:00
2026-04-15 15:28:42 +02:00
2026-04-02 23:27:07 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-15 15:28:42 +02:00
2026-04-16 22:25:21 +02:00
2026-04-16 18:42:37 +02:00
2026-04-16 13:32:14 +02:00
2026-04-17 11:37:06 +02:00
2026-04-19 15:26:00 +02:00
2026-04-20 18:04:17 +02:00
2026-04-20 12:12:21 +02:00
2026-04-20 21:54:09 +02:00
2026-04-21 09:49:47 +02:00
2026-04-21 16:56:53 +02:00
2026-04-21 23:10:55 +02:00
2026-04-22 21:14:11 +02:00
2026-04-22 15:39:31 +02:00
2026-04-23 16:54:42 +02:00
2026-04-23 11:49:12 +02:00
2026-04-23 15:42:06 +02:00
2026-04-23 09:41:43 +02:00
2026-04-26 10:09:28 +02:00
2026-04-26 18:46:55 +02:00
2026-04-26 12:07:35 +02:00
2026-04-27 09:01:52 +02:00