<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
#email-body { min-width: 30em !important; }
#email-page { padding: 8px !important; }
#email-banner { padding: 8px 8px 0 8px !important; }
#email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
#email-fields { padding: 0 8px 8px 8px !important; }
#email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
<tr valign="top">
<td id="email-page" style="padding:16px !important;">
<table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
<tr valign="top">
<td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
</tr><tr valign="top">
<td id="email-banner" style="padding:32px 32px 0 32px;">
<table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
<div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
<a class="user-hover" rel="cantor.2@osu.edu" id="email_cantor.2@osu.edu" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=cantor.2%40osu.edu" style="color:#326ca6;">Scott Cantor</a>
edited a comment on <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/newfeature.png" height="16" width="16" border="0" align="absmiddle" alt="New Feature"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-224'>IDP-224</a>
</div>
<div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
<a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-224'><strong>SAML 2 Logout Profile Actions</strong></a>
</div>
</td>
</tr>
</table>
</td>
</tr>
<tr valign="top">
<td id="email-fields" style="padding:0 32px 32px 32px;">
<table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
<tr valign="top">
<td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
<td>
<table border="0" cellpadding="0" cellspacing="0" width="100%">
<tr valign="top">
<td colspan="2" style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 16px 0;width:100%;">
<div class="comment-block" style="background-color:#edf5ff;border:1px solid #dddddd;color:#000000;padding:12px;"><p>What's done:</p>
<ul class="alternate" type="square">
        <li>proprietary flow at /profile/Logout triggering logout of the session associated with client</li>
        <li>SAML 2 LogoutRequest processing at /profile/SAML2/*/SLO triggering logout of all sessions matching input NameID/SessionIndex (front and back channel)</li>
</ul>
<p>Both of these flows optionally decorate the context tree with metadata for each SP associated with the SPSession(s) associated with the IdPSession(s) involved in the logout, and the logout view has examples of displaying UIInfo for each SP.</p>
<ul class="alternate" type="square">
        <li>SAML 2 front-channel LogoutResponse processing at /profile/SAML2/*/SLO that returns an empty document with a 200/500 status code depending on SAML StatusCode</li>
</ul>
<ul class="alternate" type="square">
        <li>a master flow at /profile/PropagateLogout that decrypts a sealed, serialized class-prefixed SPSession object from a query string parameter, deserializes it, and looks for a compatible "propagation" flow to call</li>
</ul>
<p>What's left:</p>
<ul class="alternate" type="square">
        <li>a SAML 2 logout propagation subflow that supports front or back channel LogoutRequest generation, including response handling for the back channel case. The result of this flow would either be an encoded LogoutRequest to an SP, or a 200/500 status code signaling the result of a back channel exchange.</li>
</ul>
<ul class="alternate" type="square">
        <li>SAML 2 back channel processing of LogoutRequest, triggering follow up of back channel requests to other SPs, and eventual LogoutResponse (thw flow exists, but without propagation)</li>
</ul>
<ul class="alternate" type="square">
        <li>enhancing the two front channel LogoutRequest flows to serialize and encrypt the SPSession objects to support a UI that invokes the master propagation flow</li>
</ul>
<ul class="alternate" type="square">
        <li>changing the logout view into a UI that somehow invokes all the logout propagation flows it can, notes the services it can't propagate a logout to somehow, and detects the overall result for the user</li>
</ul>
</div>
<div style="color:#505050;padding:4px 0 0 0;"> </div>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td><!-- End #email-page -->
</tr>
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
This message is automatically generated by JIRA.<br />
If you think it was sent incorrectly, please contact your JIRA administrators<br />
For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
</td>
</tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->