You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2登出流程中点击NO后自定义重定向地址的实现咨询

Customize Redirect When Denying Logout in WSO2 Identity Server

Alright, let's figure out how to set a custom redirect when clicking the NO button in WSO2's logout flow—since you already know post_redirection_uri only works for the YES button, and you're dealing with that "WSO2 End User denied the logout request" scenario. Here's what you need to do:

  • First, access the logout confirmation page file
    Navigate to your WSO2 IS installation directory, then go to <IS_HOME>/repository/deployment/server/webapps/authenticationendpoint/WEB-INF/jsp/. You'll find logout_confirm.jsp here—this is the page that displays the "Are you sure you want to logout?" prompt.

  • Adjust the NO button's behavior
    Open that JSP file and locate the section handling the NO button. By default, it submits a form to logout.do with a deny=true parameter, which triggers the default redirect and the denial message. You have two straightforward options:

    1. Direct link (quickest fix)
      Replace the NO button's form with a direct link to your custom URL. This skips backend denial processing but gets the redirect working immediately:

      <a href="https://your-custom-redirect-url.com" class="btn btn-secondary">NO</a>
      

      Note: Use this if you don't need the system to track that the logout was denied.

    2. Form submission with custom redirect (preserves backend logic)
      Keep the form but add a hidden parameter for your custom URL, then modify the backend handler to use it when denial occurs. Update the form like this:

      <form action="<%=request.getContextPath()%>/logout.do" method="post" id="denyLogoutForm">
          <input type="hidden" name="deny" value="true"/>
          <input type="hidden" name="custom_deny_redirect" value="https://your-custom-redirect-url.com"/>
      </form>
      

      Next, extend WSO2's default LogoutAction class (part of the authentication endpoint) to check for the custom_deny_redirect parameter when deny=true is present. In your custom implementation, send a 302 redirect response to your specified URL instead of using the default.

  • Optional: Customize the denial message
    If you want to change the "WSO2 End User denied the logout request" text, edit the messages.properties file at <IS_HOME>/repository/deployment/server/webapps/authenticationendpoint/WEB-INF/classes and update the value for logout.denied.message.

  • Test the flow
    Save your changes, restart WSO2 IS, then initiate a logout request. Click the NO button and verify it redirects to your custom URL as expected.


内容的提问来源于stack exchange,提问作者dtechlearn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:24:11