<p>Could you elaborate on what you mean by a java filter Scott? Do you mean a servlet filter in a custom login handler which sets/changes the idp_session cookie set by the core code?</p>
<div class="gmail_quote">On Aug 5, 2013 11:05 PM, &quot;Cantor, Scott&quot; &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt; wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
On 8/5/13 4:54 PM, &quot;Byte Flinger&quot; &lt;<a href="mailto:byteflinger@gmail.com">byteflinger@gmail.com</a>&gt; wrote:<br>
<br>
&gt;I have made some tests myself using latest chrome and, at least with its<br>
&gt;default cookie settings, it removed the cookie after closing it.<br>
<br>
That would be news to me, everybody has indicated Chrome doesn&#39;t do this<br>
anymore.<br>
<br>
&gt;I know that due to the open nature of Shibboleth I could literally just<br>
&gt;change the code but I was thinking more along the lines of something<br>
&gt;simpler like extending the username/password login handler. I thought the<br>
&gt;idp_session cookie code was at Shibboleth&#39;s<br>
&gt; core but maybe I need to look at the code again.<br>
<br>
It is in the core. The only viable way would probably a Java filter.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>