SP Logout, redirecting to the IDP
Peter Schober
peter.schober at univie.ac.at
Wed Jan 14 10:40:20 EST 2015
* Steven Carmody <steven_carmody at brown.edu> [2015-01-14 16:27]:
> Is there any chance that the SP, when it does this redirect, could add
> an attribute to the redirect url telling the IDP the entityID value of
> the SP which is doing the redirect to the Logout endpoint ?
In the SAML case there is a SAML protocol message, from which it's
clear who the issuer is.
For the non-SAML case that would probably be as useful as checking the
HTTP Referer header, so you could do just that instead?
-peter
More information about the users
mailing list