[IDENTITY-7909] Scope logout revocation to the CLI Auth0 client - #3432
Draft
Matt Carle (mcarle) wants to merge 1 commit into
Draft
[IDENTITY-7909] Scope logout revocation to the CLI Auth0 client#3432Matt Carle (mcarle) wants to merge 1 commit into
Matt Carle (mcarle) wants to merge 1 commit into
Conversation
DELETE /api/sessions revokes every rotating refresh token for the user, so logging out of the terminal also tore down the browser session. Call DELETE /api/iam/v2/sessions with the CLI client_id instead, which scopes revocation to the CLI. Gov environments keep the Okta path. Revocation failures no longer abort logout; local credentials are cleared either way and the failure is reported on stderr. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Matt Carle (mcarle)
requested review from
Jeremy Liang (JeremyLiang0105),
Rui Zhang (RuiR),
Amelia Dong (ameliadong97),
Fazal Ali (faali1),
Gilbert Wang (gilbertwang0159),
Jeff Huang (jeffhuang26),
Kala Muthukrishnan (kmuthukrishnan-blip) and
Taohao Wang (taohaowang)
and
a lite review from Copilot
August 7, 2026 19:52
|
🎉 All Contributor License Agreements have been signed. Ready to merge. |
There was a problem hiding this comment.
Pull request overview
Updates confluent logout (Confluent Cloud only) to revoke sessions via the IAM v2 sessions endpoint with an explicit Auth0 client_id, so logout only revokes the CLI’s own session rather than all refresh tokens for the account.
Changes:
- Switches cloud logout revocation from the v1
/api/sessionspath toDELETE /api/iam/v2/sessions?client_id=.... - Makes remote revocation best-effort (warnings on failure) while always clearing local credentials.
- Extends unit + integration test coverage by adding a new mocked route/handler and direct request-shape tests.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| internal/logout/command.go | Implements the new DELETE /api/iam/v2/sessions revocation flow and makes revocation failures non-fatal to local logout. |
| internal/logout/command_test.go | Adds unit tests for the new delete-session request shape and status-code handling. |
| test/test-server/ccloud_router.go | Registers the new /api/iam/v2/sessions route in the integration-test server router. |
| test/test-server/ccloud_handlers.go | Adds a handler asserting the DELETE method and presence of client_id for /api/iam/v2/sessions. |
Suppressed comments (1)
internal/logout/command_test.go:72
- This test currently hard-codes the expected Auth0 client_id string. Deriving the expected value via the same sso helper used by deleteSession() avoids duplicating constants and keeps the test resilient to future client ID updates.
// A httptest URL matches no known environment, so the client ID falls through to prod's.
require.Equal(t, "oX2nvSKl5jvBKVgwehZfvR4K8RhsZIEs", req.URL.Query().Get("client_id"))
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
3
to
7
| import ( | ||
| "net/http" | ||
| "net/http/httptest" | ||
| "testing" | ||
|
|
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Release Notes
Bug Fixes
confluent logoutnow revokes only the CLI's own Confluent Cloud session. It previously revoked every Auth0 refresh token for the account, which signed the user out of the web UI and other clients as well.Checklist
Whatsection below whether this PR applies to Confluent Cloud, Confluent Platform, or both.Test & Reviewsection below.Blast Radiussection below.This PR must not merge until cc-flow-service#3440 is deployed to prod. See
References.What
Confluent Cloud only; Confluent Platform and gov (Okta) logout are untouched.
confluent logoutcalledDELETE /api/sessions, which revokes every rotating refresh token belonging to the user's email across all Auth0 clients. Logging out of a terminal therefore also tore down the user's browser session and any IDE-plugin sessions.DELETE /iam/v2/sessionsscopes revocation to a single Auth0 client when given a client ID. This switches the Auth0 logout path to that endpoint, passing the CLI's own client ID — the same value already sent to cc-flow-service at login inpkg/auth/auth_token_handler.go. The session JWT rides along as a bearer token via the existing OAuth2 transport onc.Client.HttpClient, so no new auth plumbing is involved.Two deliberate behaviour changes beyond the endpoint swap:
Revocation failures no longer abort logout. Previously a transport error returned before local credentials were cleared, leaving the user logged in locally with no way to log out offline. The v1 SDK also swallowed non-200 responses entirely, so server-side failures were invisible. Now local credentials are always cleared, and a failure is both logged and printed to stderr — the user is told their remote session may still be active. Exit code stays 0 so scripted
logoutcalls don't start failing on a transient error.Any 2xx counts as success. The endpoint returns 200 today; accepting the range avoids a false failure if it ever returns 204.
The request is hand-rolled rather than routed through an SDK.
ccloud-sdk-go-v1-publichas no v2 sessions method, and the generatedSessionsV2Apiinccloud-sdk-go-v2-internalonly exposesCreateV2Session(POST) — there is no generated DELETE, and that module isn't currently a dependency of the CLI. Happy to move this intoccloud-sdk-go-v1-publicas aLogoutV2method if reviewers would rather keep all session calls behindClient.Auth; it just costs an extra repo and release.Blast Radius
Confluent Cloud users running
confluent logout. If the new endpoint misbehaves, logout still completes locally — credentials are removed and the user sees a warning — but the Auth0 session and refresh tokens may survive until they expire on their own (30 minutes for refresh tokens, up to 8 hours for the Auth0 session). The failure mode is a session that outlives the logout, not a user who cannot log out.Gov/FedRAMP users are unaffected:
sso.IsOktastill routes them toDELETE /api/okta/auth/sessions, and the upstream revocation RPCs reject FedRAMP calls regardless.If this ships before cc-flow-service#3440 reaches prod, the
client_idparameter is ignored and revocation silently falls back to the old unscoped behaviour — no error, but no improvement either. That is the reason for the merge gate above.References
client_idquery param toDELETE /iam/v2/sessionsTest & Review
Unit tests in
internal/logout/command_test.gocover the request shape (method, path,client_id), a 204 response, and a non-2xx response surfacing an error.The test server gained a
/api/iam/v2/sessionsroute asserting the method and a non-emptyclient_id, so the existing logout integration tests now exercise the new path end to end. I confirmed the route is genuinely reached by temporarily failing inside the handler and watching the suite fail — worth noting because a handler that is never called would otherwise pass silently.Not yet verified against a deployed environment — that needs cc-flow-service#3440 in devel first, and I'll do that before marking this ready for review.
Two pre-existing failures in my local environment, both reproduced on an unmodified
maincheckout and unrelated to this change:pkg/flink/internal/controllerpanics withopen /dev/tty: device not configured(needs a real TTY).make lint-gofails withcan't load config: unsupported version of the configuration(local golangci-lint version vs.golangci.yml).go vet ./...is clean.