<html><head></head><body><div style="font-family:verdana, helvetica, sans-serif;font-size:13px;"><div><div>Can SP pass the value of session expiry time to backend?</div><div><br></div><div>Thanks,</div>William</div>
            <div><br></div><div><br></div>
            
            <div id="ydp16a69c94yahoo_quoted_9604825777" class="ydp16a69c94yahoo_quoted">
                <div style="font-family:'Helvetica Neue', Helvetica, Arial, sans-serif;font-size:13px;color:#26282a;">
                    
                    <div>
                        On Tuesday, February 13, 2018, 7:42:55 PM EST, Cantor, Scott <cantor.2@osu.edu> wrote:
                    </div>
                    <div><br></div>
                    <div><br></div>
                    <div><div dir="ltr">> Another way to do it is for the application itself to keep track of its state,<br clear="none">> which is how we do it in our AngularJS apps.  Well, we do a few things.<br clear="none">> (We're not dealing with a Shibboleth SP, but we still have to deal with the<br clear="none">> situation where a session -- in our case, an OAuth access token -- has<br clear="none">> expired.)<br clear="none"><br clear="none">That was my meaning in saying "take over the session management", it has to be something the app deals with instead of leaving it to involuntary behavior.<br clear="none"> <br clear="none">> (Our model would be more like what Scott suggests, where you don't use<br clear="none">> the SP for session management.  Use lazy sessions, and your backend can<br clear="none">> signal back to the AngularJS app when the session has expired and it's time to<br clear="none">> do re-auth.)<br clear="none"><br clear="none">From an SP perspective, yes, the passive behavior allows a fair amount of continued reuse of the SP machinery, but you can control when the redirects actually happen.<div class="ydp16a69c94yqt8936518765" id="ydp16a69c94yqtfd27815"><br clear="none"><br clear="none">-- Scott<br clear="none"><br clear="none"><br clear="none">-- <br clear="none">For Consortium Member technical support, see <a shape="rect" href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="nofollow" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br clear="none">To unsubscribe from this list send an email to <a shape="rect" href="mailto:users-unsubscribe@shibboleth.net" rel="nofollow" target="_blank">users-unsubscribe@shibboleth.net</a><br clear="none"></div></div></div>
                </div>
            </div></div></body></html>