SLO observations

Peter Schober peter.schober at univie.ac.at
Wed Feb 24 11:35:12 EST 2016


* Cantor, Scott <cantor.2 at osu.edu> [2016-02-24 17:21]:
> The point wasn't to make SLO work later, the user has just said they
> don't want SLO

(right now)

> The reason for removing the session as soon as possible was to
> ensure that it in fact got removed if the user doesn't actually
> respond to the question because the general sense of everybody has
> always seemed to be "at all costs, kill the SSO".

Fair enough. If those people knew that they hereby have removed any
chance of also getting rid of any SP sessions, I claim that they might
reconsider.

> The Yes/No prompt Marvin included was interpreted by me not as
> whether to logout or not, but whether to propagate. It's simply a
> different question being asked than you both seem to have assigned
> to it.

I haven't actually seen it yet and was just going by what PeterM
wrote.
His expectation matches exactly the behaviour I included in Univie's
IDP for local logout years ago, though, so that's probably why I
sympathize with it. (FWIW, that local logout page didn't offer two
buttons/choices, just one to actually perform the logout, plus text to
inform the subject to otherwise just continue their work.)

> > Why even ask if you've prevent 1 of the 2 possible outcomes from
> > working in the future anyway?
> 
> That's just the question it was actually asking. Personally, I have
> a hard time with the whole "logout should be local" idea, and I'm
> not sure I would even bother presenting that choice at all, at which
> point I guess this distinction would be moot.
> 
> I'm not going to quibble over "bad" and "more bad" though.

I think a point can be made that the current behaviour is in fact
incomprehensible and confusing (and arguably not more secure when
unconditionally destroying the SP-tracking information.)

PeterM: Could you please file two separate issues, one for each?

-peter


More information about the users mailing list