2 ms·
There is no good spec. There are several conventions that are almost always IdP specific. That said, you hit on the main point: The best way to handle Single L
by krinchan 5y ago
There is no good spec. There are several conventions that are almost always IdP specific.
That said, you hit on the main point: The best way to handle Single Log Out is to not handle single log out. If I log out of a federated AWS session, I am not logged out of Okta. If I log out of Okta, I am not logged out AWS.
Unfortunately, someone saw SLO was a feature and ordered us to enable it and provide support to the SPs to implement it against my recommendations to do otherwise and here we are.