Search Results :

×

Managing user sessions securely across multiple web applications is a crucial requirement for modern organizations. Without proper session termination, a logged-out user may still have active sessions on connected platforms, creating serious security vulnerabilities and compliance risks.

Single Logout (SLO) with Backchannel Logout Support solves this by enabling automatic, server-side session termination across all connected Joomla websites the moment a logout event is triggered, either by the user or by an administrator from the Keycloak admin console. This ensures no residual sessions remain active across any application in the ecosystem, providing complete, synchronized, and secure logout functionality without requiring any additional action from the end user.

To enable Single Logout (SLO) with Backchannel Logout Support Between Keycloak and Joomla, you will need the following:

usecase card logo

miniOrange OAuth Client Extension for Joomla

Download Extension

The core challenge in multi-application environments is maintaining consistent and synchronized session states across all connected Joomla websites integrated with Keycloak as the Identity Provider (IDP).

When a user authenticates through Keycloak and is simultaneously logged into multiple Joomla websites configured under the same OAuth application, logging out from one site does not automatically terminate active sessions on the other connected sites. This creates a critical security gap that a malicious actor or unauthorized user could exploit, and still-active sessions could be used to regain access to protected resources.

Furthermore, IT administrators often need to forcefully terminate all active sessions for a specific user directly from the Keycloak admin console, for example, in cases of a compromised account or a policy violation. Without backchannel logout support, these forced terminations from Keycloak do not propagate to the connected Joomla sites, leaving those sessions alive and accessible.

The miniOrange OAuth & OpenID Connect SSO plugin for Joomla supports the OpenID Connect Backchannel Logout specification, enabling direct server-to-server logout notifications from Keycloak to every registered Joomla site. Since this mechanism operates entirely server-side, it does not depend on the user's browser being active or redirected, making it far more reliable and secure than front-channel logout methods.


Step 1: Install and activate the miniOrange OAuth & OpenID Connect SSO plugin on all Joomla websites that are integrated with the Keycloak Identity Provider.


Step 2: In the plugin's configuration panel, navigate to the Single Logout (SLO) section and enable the Backchannel Logout Support option.


Step 3: Copy the unique Backchannel Logout URL generated by the plugin for each Joomla site and register it in the corresponding Keycloak client settings under Backchannel Logout URL.


Step 4: In Keycloak, enable the Backchannel Logout Session Required option to ensure that valid session identifiers are included in all logout tokens sent to the registered endpoints.


Step 5: Repeat the configuration for every additional Joomla website connected to the same Keycloak OAuth application.


Once fully configured, the logout flow works as follows: when a user logs out from any connected Joomla site, or when an administrator forcefully ends the session from the Keycloak admin console, Keycloak dispatches a signed logout token to the backchannel logout endpoints of all registered Joomla sites. The miniOrange plugin on each site processes this token and immediately invalidates the user's active session, logging them out from all connected sites simultaneously and securely.

Implementing Single Logout (SLO) with Backchannel Logout Support between Keycloak and Joomla ensures complete, synchronized session termination across all connected applications in real time. Whether a user initiates a logout from any Joomla website or an administrator forcefully ends the session from the Keycloak admin console, all active sessions across every linked Joomla site are immediately and securely invalidated. This eliminates residual session vulnerabilities, strengthens overall security posture, ensures compliance with modern authentication standards, and delivers a seamless and trustworthy experience for both end users and administrators.

  1. SAML Single Sign-On for Joomla
  2. Access Security via Compartmentalization - OAuth Protocol in Joomla!
  3. SAML vs OAuth in Joomla: Which should you choose?
  4. Check out our documentation

We'll Reach Out to You at the Earliest

mo-form

 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

Table of Contents

Hello there!

Need Help? We are right here!

support