Keycloak - template for handling an already logged in user

Viewed 597

Using keycloak 11 I tried to find the page for the already logged in user. I want to customize this page but I fail to find it. I looked into the message to find the message, and I did its called alreadyLoggedIn. I tried looking into each template belonging to the base/login folder but I still didn't find the variable. So I supposed its set somewhere in the code but I didn't find anything in the doc or the forums.

anyone please provide the template name and/or its location in the keycloak repo ?

2 Answers

The page you are looking for is template.ftl. The content of alreadyLoggedIn is in h1#kc-page-title and set by a nested header.

The info.ftl page is the one being used for ALREADY_LOGGED_IN message. The template.ftl is never directly used for showing any page from what I know.

You can see from the source code

    /**
     * Verifies that the authentication session has not yet been converted to user session, in other words
     * that the user has not yet completed authentication and logged in.
     */
    public static <T extends JsonWebToken> void checkNotLoggedInYet(ActionTokenContext<T> context, AuthenticationSessionModel authSessionFromCookie, String authSessionId) throws VerificationException {
        if (authSessionId == null) {
            return;
        }

        UserSessionModel userSession = context.getSession().sessions().getUserSession(context.getRealm(), authSessionId);
        boolean hasNoRequiredActions =
          (userSession == null || userSession.getUser().getRequiredActionsStream().count() == 0)
          &&
          (authSessionFromCookie == null || authSessionFromCookie.getRequiredActions() == null || authSessionFromCookie.getRequiredActions().isEmpty());

        if (userSession != null && hasNoRequiredActions) {
            LoginFormsProvider loginForm = context.getSession().getProvider(LoginFormsProvider.class).setAuthenticationSession(context.getAuthenticationSession())
              .setSuccess(Messages.ALREADY_LOGGED_IN);

            if (context.getSession().getContext().getClient() == null) {
                loginForm.setAttribute(Constants.SKIP_LINK, true);
            }

            throw new LoginActionsServiceException(loginForm.createInfoPage());
            // ^^ createInfoPage is being called
        }
    }
Related