Problem/Motivation
On subdirectory-based multisites (e.g. example.com/subsite/), logout redirects drop the path prefix, sending users to the root site instead of the correct subsite.
The three affected locations:
- SimplesamlSubscriber::checkAuthStatus(): hardcoded '/' in a RedirectResponse
- SimplesamlphpDrupalAuth::externalRegister(): username collision branch (~line 176) calls logout(base_path())
- SimplesamlphpDrupalAuth::externalRegister(): registration disabled branch (~line 210) calls <code>logout(base_path())
Steps to reproduce
1. Set up a Drupal multisite with a path prefix (e.g. example.com/subsite/).
2. Log in via SAML SSO on the prefixed subsite.
3. Expire the SAML session (delete the SimpleSAMLSessionID cookie).
4. Refresh any authenticated page.
5. Observe redirect goes to example.com/ instead of example.com/subsite/.
Proposed resolution
Inject RequestStack into both classes and replace base_path() / '/' with
$this->requestStack->getCurrentRequest()->getBasePath() . '/'.
Issue fork simplesamlphp_auth-3592600
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
nord102Comment #4
nord102Updated the MR with an additional improvement, rather than always redirecting to the homepage on session expiry, the redirect now only goes to the homepage if the current route requires authentication (via
_user_is_logged_in,_admin_route,_role, or_permissionrequirements). For publicly accessible routes, the user is redirected back to the same URI so they stay on the page as anonymous.