Skip to content

Ask for login details after logging out - #3851

Open
allan-on wants to merge 3 commits into
mainfrom
bugfix/3848-ask-for-login-details-after-logout
Open

allan-on wants to merge 3 commits into
mainfrom
bugfix/3848-ask-for-login-details-after-logout

Conversation

@allan-on

@allan-on allan-on commented Aug 12, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #3848

Tapping Logout showed the login screen for a moment and then went back to the home screen. The user was never asked for their details and was never really logged out.

The saved session stays valid for a while after logging out, and the login screen treats a valid session as a reason to go straight to the home screen.

What changed

  • The app now remembers when a user logs out, and when their session PIN is deleted.
  • While that is remembered, the login screen asks for login details instead of returning to the home screen.
  • Logging in, or unlocking with a PIN, clears it.
  • Logging out now finishes even when the server cannot be reached.

This also brings in the change from #3773, which this fix depends on, so that PR can be closed as superseded. One line from #3773 was left out on purpose: secureSharedPreference.deleteCredentials() inside logout().
That entry is what findAccount() uses to match the account, so clearing it stops offline login from working and leaves the online and offline logout paths in different states.
The marker added here meets the same goal directly.

Engineer Checklist

  • I have written Unit tests for any new feature(s) and edge cases for bug fixes
  • I have added any strings visible on UI components to the strings.xml file
  • I have updated the CHANGELOG.md file for any notable changes to the codebase
  • I have run ./gradlew spotlessApply and ./gradlew spotlessCheck to check my code follows the project's style guide
  • I have built and run the FHIRCore app to verify my change fixes the issue and/or does not break the app
  • I have checked that this PR does NOT introduce breaking changes that require an update to Content and/or Configs?

Code Reviewer Checklist

  • I have verified Unit tests have been written for any new feature(s) and edge cases
  • I have verified any strings visible on UI components are in the strings.xml file
  • I have verifed the CHANGELOG.md file has any notable changes to the codebase
  • I have verified the solution has been implemented in a configurable and generic way for reuseable components
  • I have built and run the FHIRCore app to verify the change fixes the issue and/or does not break the app

Reopening the app asked for login details again even when the previous
session had not expired.

Go straight to the home screen when the saved session is still valid and
a pin is not in use. A missing account now counts as no session, so a
fresh install does not fail this check.
The saved session stays valid for a while after a user logs out, so the
login screen sent them straight back to the home screen without asking
for anything.

Save a marker when a user logs out and when their session pin is
deleted, and skip the automatic return to the home screen while that
marker is set. Logging in or unlocking with a pin clears it.
Logging out only completed when the server accepted the request. A
timeout or a failed secure connection crashed the app, and a rejected
request left the user on the settings screen still signed in.

Catch every connection error and always sign the user out on the
device, whatever the server replies.
@allan-on allan-on mentioned this pull request Aug 12, 2026
11 tasks
@codecov

codecov Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 21.73913% with 18 lines in your changes missing coverage. Please review.
✅ Project coverage is 24.6%. Comparing base (aaebbb6) to head (ed340b3).
⚠️ Report is 12 commits behind head on main.

Files with missing lines Patch % Lines
...register/fhircore/quest/ui/login/LoginViewModel.kt 0.0% 6 Missing ⚠️
...rcore/quest/ui/usersetting/UserSettingViewModel.kt 0.0% 5 Missing ⚠️
...tregister/fhircore/quest/ui/login/LoginActivity.kt 0.0% 3 Missing ⚠️
...er/fhircore/quest/ui/login/AccountAuthenticator.kt 0.0% 2 Missing ⚠️
...martregister/fhircore/quest/ui/pin/PinViewModel.kt 0.0% 2 Missing ⚠️
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff            @@
##              main   #3851     +/-   ##
=========================================
- Coverage     25.0%   24.6%   -0.5%     
- Complexity     844     850      +6     
=========================================
  Files          297     305      +8     
  Lines        16102   16564    +462     
  Branches      2689    2765     +76     
=========================================
+ Hits          4038    4081     +43     
- Misses       11580   11999    +419     
  Partials       484     484             
Flag Coverage Δ
engine 60.7% <100.0%> (-0.3%) ⬇️
geowidget 21.6% <ø> (+3.0%) ⬆️
quest 4.7% <0.0%> (+<0.1%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
...re/engine/data/remote/shared/TokenAuthenticator.kt 74.6% <100.0%> (+0.1%) ⬆️
...gister/fhircore/engine/util/SharedPreferenceKey.kt 100.0% <100.0%> (ø)
...er/fhircore/quest/ui/login/AccountAuthenticator.kt 0.0% <0.0%> (ø)
...martregister/fhircore/quest/ui/pin/PinViewModel.kt 4.0% <0.0%> (-0.2%) ⬇️
...tregister/fhircore/quest/ui/login/LoginActivity.kt 1.7% <0.0%> (-0.1%) ⬇️
...rcore/quest/ui/usersetting/UserSettingViewModel.kt 2.8% <0.0%> (-0.1%) ⬇️
...register/fhircore/quest/ui/login/LoginViewModel.kt 1.1% <0.0%> (+<0.1%) ⬆️

... and 8 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Logout does not log the user out. The app returns to the home screen

1 participant