Single Logout
Cantor, Scott
cantor.2 at osu.edu
Mon Dec 1 10:19:40 EST 2014
On 12/1/14, 2:54 PM, "Ted Fisher" <tffishe at bgsu.edu> wrote:
>
>But, we have an increasing number of outsourced applications over which
>we have no control and often having an application session that persists
>when the SP session has been ended. This is making our global logout
>attempt to fall more and more into the “even impossible” category.
>
>How are others handling this kind of scenario?
>Is the notion of SLO – particularly in a multi-vendor hodge-podge
>non-homogenous mess of applications – truly altogether impossible as the
>Shibboleth docs repeatedly imply?
Well, we didn't say it because we were trolling people. It's the reality
of the situation.
If you want a concrete suggestion, I'll make the same one I always make.
Convince the browsers to fix it. One new cookie attribute (like HttpOnly,
maybe call it Auth) and a button and we're done. They have the power to
fix this, we don't.
Honestly, we should probably just build the browser add-on ourselves at
this point (we can't do anything about the cookie attribute, but cookie
clearing is good enough for shared machines, which is what this problem is
really about).
-- Scott
More information about the users
mailing list