providers/oauth: skip post logout redirect matching if none are saved on the provider (#22718)

skip post logout redirect matching if none are saved on the provider
This commit is contained in:
Connor Peshek
2026-06-09 11:36:01 -05:00
committed by GitHub
parent 284896176e
commit f6d7edd4d8
@@ -84,8 +84,7 @@ class EndSessionView(PolicyAccessView):
"id_token_hint_decode_failed"
) from None
# Validate post_logout_redirect_uri against registered URIs
if request_redirect_uri:
if request_redirect_uri and self.provider.post_logout_redirect_uris:
# OIDC Certification: id_token_hint required with post_logout_redirect_uri
if not id_token_hint:
raise TokenError("invalid_request").with_cause("id_token_hint_missing")