[ https://issues.apache.org/jira/browse/GUACAMOLE-1266?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17860137#comment-17860137 ]
Tribhuwan Phulera commented on GUACAMOLE-1266: ---------------------------------------------- The method I mentioned earlier isn't really the right fix for the SAML logout process. Normally, logging out with SAML involves sending a SAML response to the identity provider (IDP) to start the logout. But because implementing the whole SAML logout flow would take too much time in my situation, I chose this workaround for now. It's a temporary fix that helps me handle the problem until we can give it more attention and sort out the real issue. > Implement SAML Single Logout > ---------------------------- > > Key: GUACAMOLE-1266 > URL: https://issues.apache.org/jira/browse/GUACAMOLE-1266 > Project: Guacamole > Issue Type: New Feature > Components: guacamole > Reporter: Michael Miklis > Priority: Minor > > The SAML Authentication Extension does not seem to have a logout function > built in. This will result in a loop. Steps to reproduce: > * connect to guacamole ULR > * Automatic redirect to IDP Signin Page happens > * login via SAML IDP to Guacamole > * Click Logoff in Guacamole > * Redirect to Guacamole Start-Page happens > * Redirect to IDP Signin Page > * User gets signed in automatically as the session on the IDP is still > existing > > The correct behaviour must be: > * connect to guacamole ULR > * Automatic redirect to IDP Signin Page happens > * login via SAML IDP to Guacamole > * Click Logoff in Guacamole > * *Redirecting to configured IDP Logoff URL* > * *IDP destroys session and redirects to Guacamole start page* > * Redirect to IDP Signin Page > * User gets signed in automatically as the session on the IDP is still > existing -- This message was sent by Atlassian Jira (v8.20.10#820010)