<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I didn't realize the ticket validation depended on the IdP session</blockquote><div><br></div><div>The main requirement for an IdPSession is for tracking an SPSession to support SLO, which is an important use case in CAS. I suppose that could be made optional, which I recall is what you did in the SAML SSO flows.</div><div><br></div><div>The other prominent case is that I couldn't figure any other way for determining a principal name other than by digging it out of the IdP session; see BuildAttributeContextAction for an example.</div><div><br></div><div>M<a href="mailto:dev-unsubscribe@shibboleth.net" target="_blank"></a><br>
</div><div><br></div></div></div>