Skip to content

LG-2412 associate SAML logout requests without session#3460

Merged
achapm merged 1 commit intomasterfrom
LG-2412_associate_saml_logout_requests
Dec 6, 2019
Merged

LG-2412 associate SAML logout requests without session#3460
achapm merged 1 commit intomasterfrom
LG-2412_associate_saml_logout_requests

Conversation

@achapm
Copy link
Contributor

@achapm achapm commented Dec 6, 2019

WHY: Currently, during logout, the requesting service provider is only available if the session is still valid. The result is that logout requests, without an active session, are treated as anonymous and the logout response does not include the requisite CSP whitelist.

@achapm achapm merged commit 68e2402 into master Dec 6, 2019
@achapm achapm deleted the LG-2412_associate_saml_logout_requests branch December 6, 2019 22:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants