specifying logout endpojnt at the IDP
Peter Schober
peter.schober at univie.ac.at
Wed Jun 13 22:25:02 BST 2012
* Peter Schober <peter.schober at univie.ac.at> [2012-06-13 23:09]:
> * Steven Carmody <Steven_Carmody at brown.edu> [2012-06-13 19:59]:
> > Presumably, an SP, if it so desired, could complete its own logout
> > sequence by redirecting to this url at an IDP ....
>
> You of course know that this leaves all the other SPs and applicatons
> the user's browser has sessions with untouched and hence vulnerable,
> by creating a false sense of security ("I did logout, so I'm good").
>
> You can put whatever extensions you want into metadata but I doubt it
> makes much sense to create a metadata extension for proprietary logout
> requests and have people implement support for your metadata extension.
...given the limitations of what this achives, mentioned above.
-peter
More information about the users
mailing list