Logout UI question for the community

Cantor, Scott cantor.2 at osu.edu
Wed Nov 30 17:47:56 EST 2016


On 11/30/16, 5:32 PM, "users on behalf of Kozlek, Vincent" <users-bounces at shibboleth.net on behalf of vkozlek at bloomu.edu> wrote:

> In my observation, in our setup, as long as browser session is ended and new browser session is started, no
> logged-in sessions remain.  Is that really not true?

You don't control whether the browser session is ended. Unless you control every device on your network or using your IdP and that's what you mean by "our setup".

> I know, it's a whole other thing to make sure users aren't restoring previous browser session on browser startup,
> and that's obviously a whole other problem.

No, that is the problem I'm referring to, and it is the norm. It certainly isn't something you can hand wave about as an edge case.

>    If not trying to explain that and telling them to completely exit their browser, what do you tell them?  Clear all
> history/cache/sessions each time they want to log out or perhaps only use a private/incognito session?

We have a KB article describing how to clear cookies, and we link to that, making it clear that anything short of that is not sufficient in the general case.

-- Scott




More information about the users mailing list