Logout UI question for the community

Andrew Morgan morgan at orst.edu
Wed Nov 30 17:32:10 EST 2016


On Wed, 30 Nov 2016, Cantor, Scott wrote:

> On 11/30/16, 5:11 PM, "users on behalf of Andrew Morgan" <users-bounces at shibboleth.net on behalf of morgan at orst.edu> wrote:
>
>>    We don't think that Single Logout will ever work with all of our SPs, so
>>    we don't plan to enable it.  :)
>
> It's not really debateable that it will ever work with all anybody's 
> SPs, but the underlying reason for my question is the idea that my 
> current "not doing SLO" logic at the IdP in tOSU's deployment would be 
> changed to "do as much SLO as I can and don't bother reporting the 
> results".
>
> It's just risk reduction. Why not do it if it's invisible (including any 
> and all errors) and at least clears a few sessions?
>
> That's a different proposition from "make it accessible", which Unicon 
> might manage to help us get fixed but I'm increasingly questioning the 
> value.
>
> Do you think you would deploy that?

Well, that's a reasonable way to look at it.  Right now, our logout page 
says that you have logged out of the authentication service, but it makes 
no mention of applications.  I suppose that is misleading our users.

If we can attempt to logout of applications, that's a good thing in most 
cases, although we have to be careful when we trigger SLO.  What URL do we 
put in each application for their application Logout button?

 	Andy



More information about the users mailing list