Implementing Canvas Session Timeout
Timothy Spear
n614cd at gmail.com
Wed Jul 29 19:24:27 UTC 2026
I am willing to bet Scott knows this better than I do.
But, in the SAML protocol technically the IdP can send session refresh,
length and other values to the SP.
However, I have never seen an SP respect them.
Tim
On Wed, Jul 29, 2026 at 3:03 PM Scott Cantor via users <users at shibboleth.net>
wrote:
> > We aren't having a problem per se... but rather our Canvas
> administrators were wanting us to impose idle and session lengths different
> from what we have configured in our IdP. It's my understanding that such
> per-service settings are expected to be controlled at the SP, not the IdP.
>
> It is physically impossible (absent bizarre polling tricks involving web
> bugs) for an IdP to have any influence over sessions with an application.
> There are advice/hints an IdP can send, but they are not enforced by the
> IdP, only by an SP/application.
>
> This is simply how the web works. Sessions are not global things, they're
> origin-based because that's how cookies work.
>
> If an application decides to let people stay logged in forever, the only
> thing that's going to stop that is logout support or literally clearing the
> browser's state locally.
>
> -- Scott
>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260729/cc4cf9e5/attachment.htm>
More information about the users
mailing list