Redirect on logout for idp3 and CAS?
cantor.2 at osu.edu
Tue Apr 12 12:10:34 EDT 2016
> Does a 'return' parameter in the logout URL seem a prudent enhancement ,
> since the NativeSP has that functionality and Jasig CAS offers that capability
> as well?
Only in the absence of SLO. I think logout should end at the IdP. For one thing, those return tricks tend to be used to cover for a very serious bug, not cleaning up the local session *before* redirecting away.
More information about the users