idpSession with emailAddress NameID
Cantor, Scott
cantor.2 at osu.edu
Thu Jul 3 13:01:10 EDT 2014
On 7/3/14, 9:35 AM, "Szerb, Tamas" <toma at rulez.org> wrote:
>
>My question, how to remediate it. We can only use emailAddress at this
>time (and SAML standard), and I believe this use case is quite typical.
Logout for us has never been a typical or even achievable use case, and
the design limitations in the old code reflect that. You can't remediate
the session limitation unless you want to go in and rewrite the code.
> I also wonder why not having eg. JSESSIONID also used as a key with the
>NameID?
There was no use of the Java session in V2 except on a short term basis
while handling a request.
-- Scott
More information about the users
mailing list