Cookie destruction

Peter Schober peter.schober at univie.ac.at
Fri Aug 10 04:39:01 EDT 2012


* Mark O'Quinn <mark1oquinn at gmail.com> [2012-08-10 02:49]:
> Yes, I'm asking that, and specially related to the single logout. I
> don't want to show to the user about closing the browser but to be
> sure no session is kept with the service provider. is that correct?

There is no real problem with logout with a single SP (and a single
IdP). Only when there could be many SPs with which the user might have
sessions and which your IdP currently has no idea about,
-peter


More information about the dev mailing list