Skip to content

GH-2333 Document clustered OIDC sessions#2352

Open
goutamadwant wants to merge 1 commit into
spring-projects:mainfrom
goutamadwant:GH-2333
Open

GH-2333 Document clustered OIDC sessions#2352
goutamadwant wants to merge 1 commit into
spring-projects:mainfrom
goutamadwant:GH-2333

Conversation

@goutamadwant

Copy link
Copy Markdown

Summary

  • Document that clustered OpenID Connect logout deployments need a shared SessionRegistry.
  • Show how to register SpringSessionBackedSessionRegistry with a Spring Session indexed repository.
  • Clarify in the Redis guide that Redis-backed authorization server data is separate from Redis-backed HTTP sessions.

Fixes gh-2333

Testing

  • git diff --check
  • ./gradlew :spring-authorization-server-docs:antora --console=plain

Document how clustered deployments using Spring Session can share SessionRegistry state for OpenID Connect logout sid validation.

Fixes spring-projectsgh-2333

Signed-off-by: Goutam Adwant <workwithgoutam@gmail.com>
@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Jun 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: waiting-for-triage An issue we've not yet triaged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OidcLogoutAuthenticationProvider fails with 400 on sid validation in a clustered Spring Authorization Server setup

2 participants