<div dir="ltr">The Shibboleth SP has the redirectLimit attribute on the <a href="https://wiki.shibboleth.net/confluence/display/SP3/Sessions">Sessions</a> element which can be used to prevent misuse of the SP to carry out phishing attacks. We used this to ensure the SP's Logout endpoint couldn't be exploited via the return parameter.<div><br></div><div>Are there any similar situations to be aware of with the IdP'sĀ available endpoints under 4.0? I do not believe that the /profile/Logout endpoint could be exploited in this way, but I do vaguely recall that a similar endpoint with a return parameter did once exist in the IdP.</div><div><br></div><div>Thanks,</div><div><br></div><div>Max Spicer</div></div>