Problem/Motivation

On subdirectory-based multisites (e.g. example.com/subsite/), logout redirects drop the path prefix, sending users to the root site instead of the correct subsite.

The three affected locations:
- SimplesamlSubscriber::checkAuthStatus(): hardcoded '/' in a RedirectResponse
- SimplesamlphpDrupalAuth::externalRegister(): username collision branch (~line 176) calls logout(base_path())
- SimplesamlphpDrupalAuth::externalRegister(): registration disabled branch (~line 210) calls <code>logout(base_path())

Steps to reproduce

1. Set up a Drupal multisite with a path prefix (e.g. example.com/subsite/).
2. Log in via SAML SSO on the prefixed subsite.
3. Expire the SAML session (delete the SimpleSAMLSessionID cookie).
4. Refresh any authenticated page.
5. Observe redirect goes to example.com/ instead of example.com/subsite/.

Proposed resolution

Inject RequestStack into both classes and replace base_path() / '/' with
$this->requestStack->getCurrentRequest()->getBasePath() . '/'.

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

nord102 created an issue. See original summary.

nord102’s picture

Status: Active » Needs review
nord102’s picture

Updated the MR with an additional improvement, rather than always redirecting to the homepage on session expiry, the redirect now only goes to the homepage if the current route requires authentication (via _user_is_logged_in, _admin_route, _role, or _permission requirements). For publicly accessible routes, the user is redirected back to the same URI so they stay on the page as anonymous.