Logout UI question for the community
Cantor, Scott
cantor.2 at osu.edu
Wed Nov 30 17:55:05 EST 2016
> If we can attempt to logout of applications, that's a good thing in most
> cases, although we have to be careful when we trigger SLO. What URL do we
> put in each application for their application Logout button?
Well, we can't control what applications do, I'm just talking solely about the UI at the IdP in the case that the application actually gets the user there, via redirect or SAML.
Mine today is more or less the same as yours, it doesn't propagate and it's explicit about that, but if I can invisibly propagate, nothing really changes for the user, but we reduce risk and I can start getting apps here on campus to enable logout if they can support it.
Which I largely control the SAML portion of since I generate their metadata anyway. My plan initially was to start an opt-in program for them where they validate it will work with me and then I go ahead and toggle my script to enable the SLO endpoints, and voila. But that plan also included a big "change the UI" effort which would generate thousands of confused users and people asking me what the point of this was while I stutter and look at my shoes. Skipping that part seems like a win.
I don't *have* to change the distribution to do this invisibly, but I suspect it will amount to a property toggle so others could do it if they wanted.
-- Scott
More information about the users
mailing list