Attribute checking based on sp location
Peter Schober
peter.schober at univie.ac.at
Wed Oct 19 08:28:55 EDT 2016
* Cantor, Scott <cantor.2 at osu.edu> [2016-10-18 18:59]:
> You don't really have to logout anyway. Just request a new login
> from the IdP and it will replace the old one.
My point (and I thought yours, too) was that if there's an SSO session
with the IDP why would the subject be authorized to access the
resource the second time around (assuming use of the same IDP)?
Automating the locallogout+send2idp process would only lead to a loop, IMO.
-peter
More information about the users
mailing list