destroying user IdP session as part of profile intercept flow

Cantor, Scott cantor.2 at osu.edu
Thu Feb 4 10:29:11 EST 2016


> Preventing SSO in the future via that result is precisely what
> I want to do for this use case. Thanks.

Ok. Is that really the goal, or is this more of a programmatic "disable SSO" case, like with a shared machine or something?

That area still needs more work to get more options in place.

Anyway, now that I'm thinking about it...I think I'm wrong, you probably can include some user-level checking in a predicate. The "should I serialize?" check is made at the time it needs to do that step, but in your case if you need attributes I think it's still probably too early.

-- Scott



More information about the users mailing list