OIDC Logout/SLO
Mike Schwartz
mike at gluu.org
Tue Nov 23 13:30:44 UTC 2021
As Scott maybe alluded, Google has proposed a new API for federated
identity in the browser that is being developed into a W3C draft, called
WebCM, that would hopfully contribute a part of the final solution to
federated logout. I wrote a quick summary blog,
https://gluu.org/3pcd-day-is-here/. I think the IETF secevents group is
another piece of the puzzle, because logout is an asynchronous use case
that can't be solved adequately in a synchronous manner.
Way better then my blog is the video I reference which goes into lots of
detail ON WebCM.
Mike
----------------
Michael Schwartz
Gluu
Founder / CEO
mike at gluu.org
https://www.linkedin.com/in/nynymike/
On 2021-11-23 06:57, Cantor, Scott wrote:
> I would imagine some of those specs are impossible to sustain given
> browser changes that are coming. If some members indicate they need it
> then it's a possible work item but there are many things in the queue
> ahead of it. Given it took us 10+ years to bother implementing SAML
> logout, I wouldn't hold my breath unless somebody shows up wanting to
> work on it.
>
> Logout is a non-solution to an unrelated problem. Shared machines
> can't be supported even with logout, and non-shared machines don't
> need it.
>
> The priority at this point is an administrative logout feature. It's a
> very reasonable complaint that we don't support that. But that's not
> this.
>
> -- Scott
More information about the dev
mailing list