No, in order to log out they just ask that you delete the cookie and 
redirect to their logout page.

The domain of the cookie is the domain of my site, not the external 
authentication service. Could there still be same-origin issues?

Thanks,
Tao

On Wednesday, September 24, 2014 10:07:26 AM UTC+1, Daniel Rus Morales 
wrote:
>
> It sounds like you have a same-origin policy issue. If the external 
> authentication site and your site have different origins you can’t delete 
> their cookies with your responses. Does not the external authentication 
> site provide you with a method to logout?
>
> On 23 Sep 2014, at 19:09, Tao Bojlen <brorb...@gmail.com <javascript:>> 
> wrote:
>
> Hi,
>
> I'm using a custom authentication backend for my Django project, and in 
> order to log out I have to delete a cookie that's set by the (external) 
> authentication site.
> Here is my view code:
>
> response = django_logout(request,
>                          next_page=post_logout_url)
> response.delete_cookie('cookie_name',
>                         domain="cookie_domain")
> return response
>
> The Set-Cookie header of the view is fine:
> cookie_name=; Domain=cookie_domain; expires=Thu, 01-Jan-1970 00:00:00 GMT; 
> Max-Age=0; Path=/
>
> But the cookie isn't changed at all - it has the same value and expiry 
> date ("end of session") as before logging out.
>
> Does anyone have any ideas about why this is happening?
>
> -- 
> You received this message because you are subscribed to the Google Groups 
> "Django users" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to django-users...@googlegroups.com <javascript:>.
> To post to this group, send email to django...@googlegroups.com 
> <javascript:>.
> Visit this group at http://groups.google.com/group/django-users.
> To view this discussion on the web visit 
> https://groups.google.com/d/msgid/django-users/1c643254-9800-4978-a236-a67d40cb973d%40googlegroups.com
>  
> <https://groups.google.com/d/msgid/django-users/1c643254-9800-4978-a236-a67d40cb973d%40googlegroups.com?utm_medium=email&utm_source=footer>
> .
> For more options, visit https://groups.google.com/d/optout.
>
>
>

-- 
You received this message because you are subscribed to the Google Groups 
"Django users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to django-users+unsubscr...@googlegroups.com.
To post to this group, send email to django-users@googlegroups.com.
Visit this group at http://groups.google.com/group/django-users.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-users/910dccb0-5251-4a5b-8273-b609532b3522%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to