[ https://issues.apache.org/jira/browse/KNOX-571?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15655246#comment-15655246 ]
Sumit Gupta commented on KNOX-571: ---------------------------------- [~lmccay], does this relate to [KNOX-763]? > UI Web pages should have a way to logout > ---------------------------------------- > > Key: KNOX-571 > URL: https://issues.apache.org/jira/browse/KNOX-571 > Project: Apache Knox > Issue Type: Improvement > Components: Server > Affects Versions: 0.7.0 > Environment: Redhat/Windows > Reporter: Jeffrey E Rodriguez > Fix For: Future > > Attachments: knox_logout_design.jpg > > > UI using Knox as a proxy should have a way to define a logout so Browser to > Knox session is invalidated and user is challenged for Authentication. This > is a web security requirement to prevent session hijacking attacks. > References > https://www.owasp.org/index.php/Session_hijacking_attack > https://owasp.org/index.php/Testing_for_logout_functionality_%28OTG-SESS-007%29 -- This message was sent by Atlassian JIRA (v6.3.4#6332)