[JIRA] Updated: (SSPCPP-402) Support front-channel SLO without cookies

Scott Cantor (JIRA) noreply at shibboleth.net
Tue Oct 30 22:40:07 EDT 2012


     [ https://issues.shibboleth.net/jira/browse/SSPCPP-402?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Scott Cantor updated SSPCPP-402:
--------------------------------

    Remaining Estimate: 0 minutes  (was: 1 day, 6 hours, 30 minutes)

> Support front-channel SLO without cookies
> -----------------------------------------
>
>                 Key: SSPCPP-402
>                 URL: https://issues.shibboleth.net/jira/browse/SSPCPP-402
>             Project: Shibboleth SP - C++
>          Issue Type: Improvement
>          Components: SAML 2.0 Logout
>            Reporter: bajnokk at idp.protectnetwork.org
>            Assignee: Scott Cantor
>             Fix For: 2.5.1
>
>   Original Estimate: 2 days
>          Time Spent: 1 hour, 30 minutes
>  Remaining Estimate: 0 minutes
>
> If the SP could terminate the session based on NameID only, then front-channel Single Logout UI implementation wouldn't require acceptance of third party cookies. The request can be authenticated based on the signature, which is also mandated by the profile.
> On the other hand, I admit that front-channel application notification is quite useless without cookies, but I think it's more a deployment issue. (There are other ways to tie the app session to the Shibboleth session.)

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira


More information about the commits mailing list