Logout UI question for the community
Kozlek, Vincent
vkozlek at bloomu.edu
Wed Nov 30 17:32:27 EST 2016
>If you think closing the browser works, I think you have the false sense of security, perhaps. There is nothing short of total destruction of browser state to accomplish a logout reliably unless you know how the browser is actually >configured (and on a shared machine that's not knowable). Not closing it, not rebooting.
In my observation, in our setup, as long as browser session is ended and new browser session is started, no logged-in sessions remain. Is that really not true?
I know, it's a whole other thing to make sure users aren't restoring previous browser session on browser startup, and that's obviously a whole other problem.
If not trying to explain that and telling them to completely exit their browser, what do you tell them? Clear all history/cache/sessions each time they want to log out or perhaps only use a private/incognito session?
More information about the users
mailing list