[tf-emc2] Re: [refeds] SAML Logout -- giving users options .....
Cantor, Scott
cantor.2 at osu.edu
Wed Sep 12 10:14:46 EDT 2012
On 9/12/12 7:38 AM, "David Simonsen" <david at wayf.dk> wrote:
>here is an idea for a different approach, suggested by Mads Freek at WAYF:
For the record, I've been suggesting it for years, even to the browser
vendors. They told me to get lost.
>It would require acceptance of a new cookie naming schema, also covering
>http authentications. Perhaps something like this_session_XYZ for session
>cookie, which should be specified somewhere (perhaps as a REFEDs RFC?).
Naming schemes are disruptive to existing systems and are just generally
poor design. All that's needed is a cookie property like HttpOnly. Call it
whatever, Authn or some such.
-- Scott
More information about the users
mailing list