<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div class="gmail_quote"><div>The main requirement for an IdPSession is for tracking an SPSession to support SLO, which is an important use case in CAS. I suppose that could be made optional, which I recall is what you did in the SAML SSO flows.<br></div></div></div></blockquote><div><br></div><div>Nevermind. It's not optional in any way in the current design. I modeled the CAS protocol ticket-granting ticket (TGT) as the IdPSession object since it serves exactly the same purpose: its existence is required to grant a service ticket, it knows the authenticated principal, and it (optionally) tracks services accessed on it.</div><div><br></div><div>M</div><div><div dir="ltr"><div class="gmail_quote"><div><br></div></div></div></div></div></div>