Cookie destruction

Chad La Joie lajoie at itumi.biz
Thu Aug 9 20:42:21 EDT 2012


I'm not 100% sure what you're asking.  I think you're asking "if I
clear all the cookies, can I be sure the IdP won't find some existing
session for the user?".  If that's the case, then yes, you can be sure
of that.  No cookie, no session.

On Thu, Aug 9, 2012 at 8:24 PM, Mark O'Quinn <mark1oquinn at gmail.com> wrote:
> Hi All,
>
> I've configured Shibboleth idp using external authentication (forceAuth =
> "true" and isPassive = "false") with google Apps and I've modified the
> idp.war to include some extra code (to catch the logout process with a
> personalized filter).
>
> When I logout from Google I'm redirected to the idp, here I delete all the
> cookies (by using the filter I created). Now, I don't close the browser and
> instead I go to gmail and try to login and I'm redirected to the idp to
> authenticate again (which is something I want to accomplish) my question is,
> can I rely on this and not tell the user to close the browser?
>
> I have tested in several browsers and I have always had to reauthenticate
> without closing the browser.
>
> Thank you for all your help.
>
> Cheers.
>
> --
> To unsubscribe from this list send an email to
> dev-unsubscribe at shibboleth.net



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the dev mailing list