Bug #48955

Feature #36172: Forge cleanup and update umbrella issue

Sign out should terminate session in forge

Added by Steffen Müller over 6 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2013-06-08
Due date:
% Done:

0%


Description

I expect the following scenario to work:

Given I am on http://forge.typo3.org
And I am logged in with SSO from typo3.org
When I click "Sign out"
Then my session on forge should be terminated
And my session on typo3.org should be kept

Instead, the forge session is kept and the typo3.org session is terminated.


Related issues

Related to forge.typo3.org - Bug #46258: Logout from forge Closed 2013-03-14

History

#1 Updated by Steffen Gebert over 6 years ago

  • Status changed from New to Under Review

This should be included in the next update

#2 Updated by Steffen Gebert over 6 years ago

  • Parent task set to #36172

#3 Updated by Steffen Müller over 5 years ago

Any news on this issue?

I would say, if I click "sign out" I would expect the session to be terminated. Imagine you do that on a shared browser (internet cafe) and someone else can abuse your user session.

#4 Updated by Steffen Gebert over 2 years ago

  • Status changed from Under Review to Resolved

This cannot be changed for the current SSO. LDAP with login directly on the sub sites will help.

#5 Updated by Steffen Gebert over 2 years ago

  • Status changed from Resolved to Closed

Also available in: Atom PDF