SLO observations

Cantor, Scott cantor.2 at osu.edu
Wed Feb 24 11:56:00 EST 2016


> * Cantor, Scott <cantor.2 at osu.edu> [2016-02-24 17:21]:
> > The point wasn't to make SLO work later, the user has just said they
> > don't want SLO
> 
> (right now)

I could argue the question you're both asking the user here belongs at the SP, not the IdP. The standard really doesn't say that an IdP that receives a LogoutRequest is supposed to ask anything. It pretty much says "the session authority MUST..."

Also, there are *two* endpoints here (3 if we include CAS), the SAML endpoint and the regular old /idp/profile/Logout endpoint. If you explicitly go to that endpoint, I'm again not clear on the point of asking. We don't ask if you want to login when we get an AuthnRequest.

> Fair enough. If those people knew that they hereby have removed any
> chance of also getting rid of any SP sessions, I claim that they might
> reconsider.

Nothing is stopping anybody from adding that text, that's a local presentation decision.

> His expectation matches exactly the behaviour I included in Univie's
> IDP for local logout years ago, though, so that's probably why I
> sympathize with it. (FWIW, that local logout page didn't offer two
> buttons/choices, just one to actually perform the logout, plus text to
> inform the subject to otherwise just continue their work.)

That's sort of my point. We're arguing over the meaning of a choice I'm not really sure about the point of asking. I don't think either question makes a great deal of sense really, and there's definitely a question in my mind about doing this in the SAML case. I left that there because it was easier than making them behave differently, but I don't like it.

I think if it gets a request to logout, it needs to do that. If in your mind that means it needs to immediately attempt SLO and communicate the overall outcome, then I think that's probably what it should do (which doesn't need a patch, just auto-select yes).

In effect, I think the request here is for a conditional logout option, which is not something we were attempting to provide, and then a statement that the current No option is bad. Since having that option there is a default, it could simply be made a non-default without actually removing it.

-- Scott



More information about the users mailing list