fix: update logout flow to use registered post-logout route and add redirect handler

This commit is contained in:
2026-05-12 11:01:34 -05:00
parent 51d29950c8
commit 2436a4d563
2 changed files with 19 additions and 2 deletions

View File

@@ -147,10 +147,14 @@ export function redirectToKeycloakAuthorization(systemBaseUrl: string, redirectP
export function buildKeycloakLogoutUrl(systemBaseUrl: string): string {
const keycloakBaseUrl = getPublicKeycloakBaseUrl();
const workspaceLoginUrl = getWorkspaceLoginUrl(systemBaseUrl, { forPostLogout: true });
// post_logout_redirect_uri must be a URI registered in the KC client.
// The workspace login URL (workspace.aduanasoft.com/login) is NOT registered there.
// Use a local /auth/post-logout route which IS covered by the app's registered wildcard,
// then that route bounces to workspace login.
const postLogoutRedirectUri = `${systemBaseUrl}/auth/post-logout`;
const params = new URLSearchParams({
client_id: getKeycloakClientId(),
post_logout_redirect_uri: workspaceLoginUrl
post_logout_redirect_uri: postLogoutRedirectUri
});
return `${keycloakBaseUrl}/realms/${getKeycloakRealm()}/protocol/openid-connect/logout?${params.toString()}`;

View File

@@ -0,0 +1,13 @@
import { redirect } from '@sveltejs/kit';
import type { RequestHandler } from './$types';
import { getWorkspaceLoginUrl } from '$lib/server/workspace-auth';
/**
* KC redirects here after completing the logout flow.
* This URL is covered by the app's registered wildcard in KC (e.g. anexo76-dev.aduanasoft.com/*).
* We then send the user to workspace login so it can apply myApps() launcher logic.
*/
export const GET: RequestHandler = async ({ request }) => {
const systemBaseUrl = new URL(request.url).origin;
throw redirect(303, getWorkspaceLoginUrl(systemBaseUrl, { forPostLogout: true }));
};