CodamAIDocs
Topicdone

Sign out

How signing out deletes cookies, how Keycloak ends the session, and why the login page does not sign you in again right away.

Variants
with ID tokenwithout ID token (confirmation page)without configured Keycloak (local only)

What this is about

At CodamAI, signing out means two things:

  1. The BFF deletes its cookies. After that, the browser no longer has a session with the user interface.
  2. Keycloak ends its session. Otherwise the next login would go through without a password, because Keycloak still knows the person.

The flow

sequenceDiagram
    participant B as Browser
    participant F as BFF
    participant K as Keycloak
    B->>F: GET /api/logout (full page change)
    F->>F: reads the ID token from the cookie
    F->>F: deletes all session cookies
    F-->>B: redirect to Keycloak /logout<br/>with id_token_hint and return address
    B->>K: /protocol/openid-connect/logout
    K->>K: ends the Keycloak session
    K-->>B: redirect to /login?loggedOut=1
    B->>F: /login?loggedOut=1
    F-->>B: login page, no automatic login

The “Sign out” button is a normal link to /api/logout, not a script action. Only this way can the server delete the httpOnly cookies and send the browser to Keycloak.

The return address after signing out is called post_logout_redirect_uri. The default is /login?loggedOut=1 of the own user interface. You can set it with NUXT_AUTH_POST_LOGOUT_REDIRECT. Keycloak accepts it only if it is listed on the client under “Valid post logout redirect URIs”.

The variants

Three ways to sign out

When: The normal case. The session contains an ID token.

  1. 1
    BFF→Keycloak
    redirects to Keycloak with id_token_hint=<ID-Token>
  2. 2
    Keycloak
    recognizes from the ID token who is signing out, and does not ask
  3. 3
    Keycloak→Browser
    returns to /login?loggedOut=1

Result: Sign-out without an intermediate page.

When: The session no longer has an ID token, for example because it was already broken.

  1. 1
    BFF→Keycloak
    redirects to Keycloak with only client_id
  2. 2
    Keycloak→User
    shows the page “Do you want to sign out?”
  3. 3
    User→Keycloak
    confirms
  4. 4
    Keycloak→Browser
    returns to /login?loggedOut=1

Result: Sign-out with a confirmation page. Without an ID token, Keycloak cannot be sure that the sign-out is intended.

When: No Keycloak address is set in the portal.

The BFF only deletes its cookies and redirects straight to /login?loggedOut=1.

Result: Signed out locally only.

What is deleted

The BFF reads the ID token before it deletes, because after that it is gone. Then it deletes every cookie whose name starts with the portal’s prefix, also with __Secure- or __Host- in front:

CookieWhat for
…session-token and its parts .0, .1, …the session with the tokens
…callback-urlthe return target during login
…csrf-tokenprotection of the login forms
…pkce.code_verifier, …state, …nonceleftovers of a started sign-in

The prefix is next-auth in the hub and in the CDMS portal, and cias-auth in the CIAS portal. See Session in the BFF and cookies.

Why you are not signed in again right away

The login page normally signs you in automatically. Right after signing out, that would be wrong. The loggedOut parameter in the address turns off the automatic login. The page then only shows the “Sign in” button.

Next

Sources in the code and the knowledge base
  • hub-frontend, CIAS/cias-frontend, CDMS/frontend – server/api/logout.get.ts, app/layouts/default.vue, app/pages/login.vue (loggedOut)
  • hub-login – theme/codamai/login/logout-confirm.ftl
Search