I think there is still work to do and the webflow changes are impacting.

Indeed, but I felt that was actually beneficial as it would allow the existing functionality to coexist with the new and allow deployment-time configuration to choose one or the other.

AJAX requests can be postponed later

Agreed

but I didn't see anything on how to mix front and back channel SLO.

I imagined a phased approach where deployers must choose one or the other initially via WAR overlay configuration, and going forward re-implementing back-channel as another flow where both could be supported simultaneously at runtime. I believe we can model logout as a single flow that dispatches to one of two subflows based on request artifacts; for example a "type" parameter. I am fairly certain we should default to front channel, but that's a detail. In that case /logout?type=back might mean back channel, while /logout?type=front or /logout would mean front channel. That's just a straw man proposal; there are numerous ways we could handle it.

In summary, I recommend we support one or the other initially for 4.0 and work to support both for the subsequent release as an iterative improvement.

I will continue your work and maybe finish it for 4.0.

I'm happy to provide support though code reviews in the near term and testing during the RC phase.

I would like to point out one important issue that needs to be resolved, for which I made a comment on the commit:

https://github.com/serac/cas/commit/7855e2293a8a14cf85bec6283fae1cb560e9156f

Let me know if you have further questions or comments.

Best,
M

--
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-dev

Reply via email to