grouper-users - Re: [grouper-users] GrouperUI performing an IDP logout when using shibb authn
Subject: Grouper Users - Open Discussion List
List archive
- From: Jeffrey T Eaton <>
- To: Eric Cheu <>
- Cc: "" <>
- Subject: Re: [grouper-users] GrouperUI performing an IDP logout when using shibb authn
- Date: Wed, 26 Nov 2014 17:44:52 +0000
- Accept-language: en-US
It's not as easy as deleting the IDP's cookies. Consider the case where a user starts a browser, and accesses 3 different SPs.
The user, while interacting with one of the SPs, wants to log out. That SP can destroy its own session state, and redirect to the IDP to delete the session state there, however, there's no currently feasible way to force a logout of the other
SPs which may be maintaining their own session.
So, now the user walks away from the shared computer, and someone else walks up and happens to navigate to one of the SPs where the previous user was logged in, and is already logged in as the other user.
The only real way to manage single sign on in a shared computer environment is to have something which forcibly resets the browser state, losing all session data for all sites. Used to be that quitting your browser would be sufficient to delete
all of the cookies, but even that's becoming less reliable with browsers trying to "helpfully" restore your previous session cookies for you.
-jeaton
|
- [grouper-users] GrouperUI performing an IDP logout when using shibb authn, Rob Gorrell, 11/19/2014
- Re: [grouper-users] GrouperUI performing an IDP logout when using shibb authn, Eric Cheu, 11/25/2014
- Re: [grouper-users] GrouperUI performing an IDP logout when using shibb authn, David Langenberg, 11/25/2014
- Re: [grouper-users] GrouperUI performing an IDP logout when using shibb authn, Jeffrey T Eaton, 11/26/2014
- Re: [grouper-users] GrouperUI performing an IDP logout when using shibb authn, Rob Gorrell, 11/26/2014
- Re: [grouper-users] GrouperUI performing an IDP logout when using shibb authn, Eric Cheu, 11/26/2014
- <Possible follow-up(s)>
- Re: [grouper-users] GrouperUI performing an IDP logout when using shibb authn, Chris Hyzer, 11/26/2014
- Re: [grouper-users] GrouperUI performing an IDP logout when using shibb authn, Eric Cheu, 11/25/2014
Archive powered by MHonArc 2.6.16.