## Description
During logout all sessions, the session should be removed from Redis,
otherwise even though the token is expired (cannot write), the user can
still read data in the application while the session (15 minutes of
refresh token) is still valid
for that we are mapping all session keys to a new entry (encrypted) in
Redis based on user information and the secret
after logout all sessions, we remove the current session from Redis
(already existing mechanism), and also read this entry to remove all
other active sessions

## Motivation and Context
AB#1625768
## How Has This Been Tested?
Locally with pics
## Checklist:
- [ ] My change requires a change to the documentation or CHANGELOG.
- [ ] I have updated the documentation/CHANGELOG accordingly.
- [x] I have created a feature (non-master) branch for my PR.
- [x] Do not stop flow if revoke fails.
- [x] Properly handle/log error
## Motivation and Context
<!--- Why is this change required? What problem does it solve? -->
<!--- If it fixes an open issue, please link to the issue here. -->
## How Has This Been Tested?
<!--- Please describe in detail how you tested your changes. -->
<!--- Include details of your testing environment, and the tests you ran
to -->
<!--- see how your change affects other areas of the code, etc. -->
## Checklist:
<!--- Go over all the following points, and put an `x` in all the boxes
that apply. -->
<!--- If you're unsure about any of these, don't hesitate to ask. We're
here to help! -->
- [ ] My change requires a change to the documentation or CHANGELOG.
- [ ] I have updated the documentation/CHANGELOG accordingly.
- [ ] I have created a feature (non-master) branch for my PR.
Adding functionality to revoke access token on logout. This will use the
newly added OAUTH2_PROXY_BACKEND_REVOKE_ACCESS_TOKEN_URL environment
variable.
AB#1624642
## Motivation and Context
Adding the functionality to revoke an access token on logout prevents an
attacker from continuing to use a stolen access token until the
expiration of the TTL.
## How Has This Been Tested?
Running it locally integrated with Pics.
<!--- Provide a general summary of your changes in the Title above -->
## Description
Change the audit code from 110123 to 110114.
## Motivation and Context
The code 110123 was not present and know by the audit log server.
after running `cf logs oauth_proxy --recent` in the
pics_client_test_us_east we saw this error:
`2025-01-14T11:06:04.64+0100 [APP/PROC/WEB/0] ERR 2025/01/14 10:06:04
Not able to send the audit message
{"issue":[{"severity":"error","code":"invalid","details":{"coding":[{"system":"https://www.hl7.org/fhir/valueset-operation-outcome.html","code":"MSG_ERROR_PARSING"}],"text":"Not
complaint with AuditEvent specification"},"diagnostics":"Not complaint
with AuditEvent specification"}],"resourceType":"OperationOutcome"}`
Unfortunately there is no error message logged in Kibana.
## How Has This Been Tested?
<!--- Please describe in detail how you tested your changes. -->
<!--- Include details of your testing environment, and the tests you ran
to -->
<!--- see how your change affects other areas of the code, etc. -->
## Checklist:
<!--- Go over all the following points, and put an `x` in all the boxes
that apply. -->
<!--- If you're unsure about any of these, don't hesitate to ask. We're
here to help! -->
- [ ] My change requires a change to the documentation or CHANGELOG.
- [ ] I have updated the documentation/CHANGELOG accordingly.
- [ ] I have created a feature (non-master) branch for my PR.
## Description
- [x] Adding audit log to logout all sessions
- [x] Updating variable name
AB#1437807
## Motivation and Context
Audit log for logout all sessions
## How Has This Been Tested?
Locally integrated with PICS. Used webhook to receive the audit entry.
## Checklist:
<!--- Go over all the following points, and put an `x` in all the boxes
that apply. -->
<!--- If you're unsure about any of these, don't hesitate to ask. We're
here to help! -->
- [x] My change requires a change to the documentation or CHANGELOG.
- [x] I have updated the documentation/CHANGELOG accordingly.
- [x] I have created a feature (non-master) branch for my PR.
<!--- Provide a general summary of your changes in the Title above -->
## Description
<!--- Describe your changes in detail -->
For Story AB#1618387
Adding function to audit log 'logout for all session'.
Reference documentation:
https://hl7.org/fhir/valueset-audit-event-type.htmlhttps://hl7.org/fhir/R4/codesystem-dicom-dcim.html#dicom-dcim-110114
## Motivation and Context
<!--- Why is this change required? What problem does it solve? -->
<!--- If it fixes an open issue, please link to the issue here. -->
## How Has This Been Tested?
Tested locally with webhook.
Build a new docker image in wsl with `docker buildx build -t
oauth-local:v0.0.3 .`
Update the docker-compose.yml file to
Updated the environment variable for .env.oauth2-proxy.us-east
Adding =>
`OAUTH2_PROXY_AUDIT_URL=https://webhook.site/0d7939ba-13f3-4cbc-ac2c-b814a3add0ca`
The audit logging is posted to the webhook =>
`
{
"resourceType": "AuditEvent",
"event": {
"type": {
"system": "http://hl7.org/fhir/ValueSet/audit-event-type",
"version": "1",
"code": "110123",
"display": "Logout",
"userSelected": "All Sessions"
},
"action": "E",
"dateTime": "2024-12-19T12:44:30Z",
"outcome": "0",
"outcomeDesc": "Success"
},
"participant": [
{
"userId": {
"value": "SECRET"
},
"altId": "SECRET",
"requestor": true
}
],
"source": {
"identifier": {
"type": {
"system": "http://hl7.org/fhir/ValueSet/audit-source-type",
"code": "4",
"display": "Application Server"
},
"value": "admin_fthv@philips.com"
},
"type": [
{
"system": "http://hl7.org/fhir/security-source-type",
"code": "1",
"display": "End-user display device, diagnostic device."
}
],
"extension": [
{
"url": "/worklist",
"extension": [
{
"url": "applicationName",
"valueString": "ReportingTest"
},
{
"url": "applicationVersion",
"valueString": "1"
},
{
"url": "serverName",
"valueString": "oauth2proxy"
},
{
"url": "componentName",
"valueString": "oauth2proxy"
},
{
"url": "productKey",
"valueString": "SECRET"
},
{
"url": "tenant",
"valueString": "SECRET"
}
]
}
]
}
}
`
## Checklist:
<!--- Go over all the following points, and put an `x` in all the boxes
that apply. -->
<!--- If you're unsure about any of these, don't hesitate to ask. We're
here to help! -->
- [ ] My change requires a change to the documentation or CHANGELOG.
- [ ] I have updated the documentation/CHANGELOG accordingly.
- [ ] I have created a feature (non-master) branch for my PR.
- [ ] I have written tests for my code changes.
## Description
Merge from Upstream/Release/7.7.1
AB#1611455
## Motivation and Context
Keeping OAuth2-Proxy up-to-date with the upstream
## How Has This Been Tested?
Created a local container image of the oauth-proxy from this PR and
integrated it with Reporting locally.
- run in the root of this repo
- docker buildx build -t oauth-local .
- Updated FROM statement in pics/src/services/Oauth2Proxy/Dockerfile to
- FROM oauth-local
The following flows were checked:
- Login
- Audit logs
- Logout
## Checklist:
- [x] Merge from Upstream/Release/7.7.1