auth_oauth_end_session: single sign-on logout

A small companion addon, independent of the connector. Odoo's OAuth login only ends the Odoo session on logout; the session at the identity provider stays, and the next sign-in logs straight back in. With an end-session URL on the provider, logging out of Odoo ends that session too.

Odoo's OAuth login (auth_oauth) only ends the Odoo session on logout. The session at the identity provider stays, so the next Sign in with … logs straight back in as the same user, without asking. On a shared terminal that is the wrong behaviour, and it is the one every Odoo behind Keycloak has by default.

Moduleauth_oauth_end_session
Depends onauth_oauth — not on the connector
InstallsBy hand
AffectsUsers who signed in through a provider with an end-session URL. Password logins are untouched
Sourceopenepcis-odoo · LGPL-3

It ships in the connector's repository because an Odoo that talks to OpenEPCIS is usually an Odoo whose users sign in through the same Keycloak, but nothing in it knows about OpenEPCIS. It is useful on its own.

Setting it up

  1. Install auth_oauth_end_session.
  2. On the OAuth provider in Odoo — Settings → Users & Companies → OAuth Providers — fill in End session URL. For Keycloak it is the realm's OpenID Connect logout endpoint:
    https://<host>/realms/<realm>/protocol/openid-connect/logout
    
  3. On the client in Keycloak, register the Odoo login page as a valid post-logout redirect URI:
    https://<odoo>/web/login
    

Logging out of Odoo then sends a user who signed in through that provider on to the end-session endpoint — OpenID Connect RP-initiated logout — and the provider returns them to Odoo's login page.

One thing to expect

Odoo's OAuth login uses the implicit flow and receives no ID token, so the logout request carries no id_token_hint. Without it, the provider may ask the user to confirm the logout rather than ending the session silently. That is the provider being careful with a request it cannot fully attribute, not a fault in the setup.

Last updated: