OIDC Logout/SLO

Mike Schwartz mike at gluu.org
Tue Nov 23 13:30:44 UTC 2021


As Scott maybe alluded, Google has proposed a new API for federated 
identity in the browser that is being developed into a W3C draft, called 
WebCM, that would hopfully contribute a part of the final solution to 
federated logout. I wrote a quick summary blog, 
https://gluu.org/3pcd-day-is-here/. I think the IETF secevents group is 
another piece of the puzzle, because logout is an asynchronous use case 
that can't be solved adequately in a synchronous manner.

Way better then my blog is the video I reference which goes into lots of 
detail ON WebCM.

Mike

----------------
Michael Schwartz
Gluu
Founder / CEO
mike at gluu.org
https://www.linkedin.com/in/nynymike/

On 2021-11-23 06:57, Cantor, Scott wrote:
> I would imagine some of those specs are impossible to sustain given
> browser changes that are coming. If some members indicate they need it
> then it's a possible work item but there are many things in the queue
> ahead of it. Given it took us 10+ years to bother implementing SAML
> logout, I wouldn't hold my breath unless somebody shows up wanting to
> work on it.
> 
> Logout is a non-solution to an unrelated problem. Shared machines
> can't be supported even with logout, and non-shared machines don't
> need it.
> 
> The priority at this point is an administrative logout feature. It's a
> very reasonable complaint that we don't support that. But that's not
> this.
> 
> -- Scott


More information about the dev mailing list