For 3.0 I have another idea though it isn't as complete at cleaning up. It should be possible to include the portlet session invalidation trigger in the Logout servlet. This would provide a request and response which can be used to do a cross-context dispatch (how all portlet rendering is done) which could invalidate the sessions of all portlet applications for the user. The downside to this approach is that if the user's session times out the corresponding portlet application sessions would be left to timeout as well though hopefully they would timeout within a short time of the portal's session.
I'd really like to hear other folks input on this issue as I'm not sure the best approach to take here.
-Eric
smime.p7s
Description: S/MIME Cryptographic Signature
