User induced session stomping?

Peter Schober peter.schober at univie.ac.at
Tue Aug 28 09:24:14 EDT 2012


* Lukas Hämmerle <lukas.haemmerle at switch.ch> [2012-08-28 14:40]:
> One reason for this probably is that more and more browsers like
> Firefox save the tabs/windows state upon quit. If a user is logged
> in on two or more Shibboleth-protected web pages that have
> configured a default Identity Provider and they quit their browser,
> this state might be saved.

Note that there have been suggestions (including patches/code) on how
to handle this (cf. https://issues.shibboleth.net/jira/browse/SIDP-446 )
but these have not been integrated into 2.x.
-peter


More information about the users mailing list