What this is about
At CodamAI, signing out means two things:
- The BFF deletes its cookies. After that, the browser no longer has a session with the user interface.
- Keycloak ends its session. Otherwise the next login would go through without a password, because Keycloak still knows the person.
The flow
sequenceDiagram
participant B as Browser
participant F as BFF
participant K as Keycloak
B->>F: GET /api/logout (full page change)
F->>F: reads the ID token from the cookie
F->>F: deletes all session cookies
F-->>B: redirect to Keycloak /logout<br/>with id_token_hint and return address
B->>K: /protocol/openid-connect/logout
K->>K: ends the Keycloak session
K-->>B: redirect to /login?loggedOut=1
B->>F: /login?loggedOut=1
F-->>B: login page, no automatic login
The “Sign out” button is a normal link to /api/logout, not a script action. Only this way can the server delete the httpOnly cookies and send the browser to Keycloak.
The return address after signing out is called post_logout_redirect_uri. The default is /login?loggedOut=1 of the own user interface. You can set it with NUXT_AUTH_POST_LOGOUT_REDIRECT. Keycloak accepts it only if it is listed on the client under “Valid post logout redirect URIs”.
The variants
When: The normal case. The session contains an ID token.
-
1BFF→Keycloakredirects to Keycloak with
id_token_hint=<ID-Token> -
2Keycloakrecognizes from the ID token who is signing out, and does not ask
-
3Keycloak→Browserreturns to
/login?loggedOut=1
Result: Sign-out without an intermediate page.
When: The session no longer has an ID token, for example because it was already broken.
-
1BFF→Keycloakredirects to Keycloak with only
client_id -
2Keycloak→Usershows the page “Do you want to sign out?”
-
3User→Keycloakconfirms
-
4Keycloak→Browserreturns to
/login?loggedOut=1
Result: Sign-out with a confirmation page. Without an ID token, Keycloak cannot be sure that the sign-out is intended.
When: No Keycloak address is set in the portal.
The BFF only deletes its cookies and redirects straight to /login?loggedOut=1.
Result: Signed out locally only.
What is deleted
The BFF reads the ID token before it deletes, because after that it is gone. Then it deletes every cookie whose name starts with the portal’s prefix, also with __Secure- or __Host- in front:
| Cookie | What for |
|---|---|
…session-token and its parts .0, .1, … | the session with the tokens |
…callback-url | the return target during login |
…csrf-token | protection of the login forms |
…pkce.code_verifier, …state, …nonce | leftovers of a started sign-in |
The prefix is next-auth in the hub and in the CDMS portal, and cias-auth in the CIAS portal. See Session in the BFF and cookies.
Why you are not signed in again right away
The login page normally signs you in automatically. Right after signing out, that would be wrong. The loggedOut parameter in the address turns off the automatic login. The page then only shows the “Sign in” button.