[Openid-specs-ab] FW: OpenID Connect HTTP-based logout

Mike Jones Michael.Jones at microsoft.com
Tue Sep 8 22:57:57 UTC 2015


Just got a good question…  How long should the OP wait when doing HTTP-based logout (doing the iframe renders) before redirecting to the post_logout_redirect_uri?  Is there HTTP state available to tell the OP when the page has finished rendering?

                                                                -- Mike

From: Patrick Gleeson [mailto:patrick.gleeson at sohohouse.com]
Sent: Tuesday, September 08, 2015 6:39 AM
To: Mike Jones
Subject: OpenID Connect HTTP-based logout


Dear Mike,



I very much enjoyed reading your spec<https://na01.safelinks.protection.outlook.com/?url=http%3a%2f%2fopenid.net%2fspecs%2fopenid-connect-logout-1_0.html&data=01%7c01%7cMichael.Jones%40microsoft.com%7cadd2cf5a8b354c34a74108d2b852f756%7c72f988bf86f141af91ab2d7cd011db47%7c1&sdata=rV49dEI76m7I1of1KVmlwvQglIcNJMCLDWb3fZ4QEBg%3d> for a mechanism for logging out users from all RPs of an OP. If you'll forgive me for my stupidity, one aspect of the spec wasn't clear to me: When the OP renders the HTML page with all the iframes, how does it know how long to wait before it can redirect to the post_logout_redirect_uri? Would it redirect the moment the page has loaded, treating the iframe requests as fire-and-forgets? Or would it wait until the iframe has loaded to try to detect whether the logout has been successful? Or is that sort of consideration beyond the scope of the spec?



If you have a moment I'd love to hear your response.



Best,



Patrick

Patrick Gleeson
[cid:image9250e8.JPG at 29f880e7.4795cbcd]<https://na01.safelinks.protection.outlook.com/?url=http%3a%2f%2fwww.sohohousedeanstreet.com&data=01%7c01%7cMichael.Jones%40microsoft.com%7cadd2cf5a8b354c34a74108d2b852f756%7c72f988bf86f141af91ab2d7cd011db47%7c1&sdata=7CgQe3YB%2f8Wzw%2bAOkxhq5QGfqJo4S1eYsgJXXjbLDbk%3d>
Soho House Terms and Conditions apply

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20150908/598abedc/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image9250e8.JPG
Type: image/jpeg
Size: 26701 bytes
Desc: image9250e8.JPG
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20150908/598abedc/attachment-0001.jpe>


More information about the Openid-specs-ab mailing list