[keycloak-user] NPE in SAMLIdentityProvider

Goovaerts C (Caroline) (RIGD-LOXIA) caroline.goovaerts at rigd-loxia.nl
Mon Feb 20 09:43:12 EST 2017


Hi all,

While implementing the single logout feature, we ran into a NPE in SAMLIdentityProvider.java.
This behavior seems to be independent of using backchannel logout, whether or not:

                at org.keycloak.broker.saml.SAMLIdentityProvider.backchannelLogout(SAMLIdentityProvider.java:154)
                at org.keycloak.broker.saml.SAMLIdentityProvider.keycloakInitiatedBrowserLogout(SAMLIdentityProvider.java:178)

In our application we invoke httpServletRequest.logout() as suggested in the guide: https://keycloak.gitbooks.io/securing-client-applications-guide/content/topics/oidc/java/logout.html.

Version info:
-          ADFS server: 3.x
-          Keycloak server: 2.3.0.Final
-          Maven Keycloak modules: 2.2.1.Final

We'd like to know:

-          Whether it is sufficient to invoke request.logout() to do a single logout

-          Why it is broken in the given setup

I could not determine whether this is related to https://issues.jboss.org/browse/KEYCLOAK-4398 or not.

Thanks & kind regards,

Caroline Goovaerts

Developer
RIGD-LOXIA


More information about the keycloak-user mailing list