Hello,

The CAS protocol for logout says it takes an optional parameter 'url' as
a +/- logout landing page.

I just noticed on one of our sites the use of

   .../logout?service=...

I was about to notify the site owners that this violated protocol
(implying it wouldn't do what they thought it did), when I tried it
myself, was logged out, and then redirected to the URL listed in the
'service' parameter.

Undocumented feature? Is the protocol page out of date? Something else?

Cf. http://www.jasig.org/cas/protocol

Thanks.
Tom.

-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-user

Reply via email to