IDP Logout, text asking user whether or not to kill the IDP session

Cantor, Scott cantor.2 at osu.edu
Tue Oct 15 21:03:43 EDT 2013


On 10/15/13 6:24 PM, "Jim Fox" <fox at washington.edu> wrote:
>
>In most cases I think closing the browser does kill off the session
>cookies.
>Are there browsers where a user cannot even configure it to work corectly?

I *think* Chrome mostly does what you tell it, but Firefox IIRC no longer
exposes the GUI option that really disables this. It appears to if you
turn off Session Restore, but the feature still works from the History
menu.

Mozilla seems to have a nasty tendency of coming up with the most
dangerous ways of implementing these behaviors.

AFAIK, neither Safari nor IE defaults to saving session cookies for https
sites. But that's always subject to change.

-- Scott




More information about the users mailing list