Integrating CAS into logout/SLO

Cantor, Scott cantor.2 at osu.edu
Wed Jun 17 17:32:15 EDT 2015


On 6/17/15, 3:16 PM, "dev on behalf of Marvin Addison" <dev-bounces at shibboleth.net on behalf of marvin.addison at gmail.com> wrote:

>I have been envisioning a CAS-specific logout flow at /profiles/cas/logout, but now I'm fairly certain I don't need one.

If all you're intending is that it be "pick up session from client request and propagate", that is indeed what the current endpoint does, minus the propagate.

We'll need admin logout stuff too, but I haven't worked on that yet, and it wouldn't be specific to CAS or SAML either, and may not even propagate except by back channel.

> Logout feels like it ought to apply to the IdP session as a whole and be protocol agnostic, and your proposed design would be consistent with that afaict. So instead of a top-level CAS logout flow, I am planning on a CAS-specific logout propagation subflow that fires when instances of CASSPSession are found in the IdPSession.

That's what I would expect.

>I would like to discuss Friday at a high level with respect to planning and execution.

Partly why I brought up doing a 3.1.2 on the committers list was to get our timelines re-established since I was hoping for this work to be in 3.2 but we're not really far along with it.

-- Scott



More information about the dev mailing list