Skip to content

Commit

Permalink
Remove SAML 2.0 Logout Default
Browse files Browse the repository at this point in the history
Closes gh-10607
  • Loading branch information
jzheaux committed Jan 14, 2022
1 parent 6c5ac0d commit 20c2529
Show file tree
Hide file tree
Showing 2 changed files with 6 additions and 1 deletion.
5 changes: 5 additions & 0 deletions docs/modules/ROOT/pages/servlet/saml2/logout.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ RelyingPartyRegistrationRepository registrations() {
RelyingPartyRegistration registration = RelyingPartyRegistrations
.fromMetadataLocation("https://ap.example.org/metadata")
.registrationId("id")
.singleLogoutServiceLocation("{baseUrl}/logout/saml2/slo")
.signingX509Credentials((signing) -> signing.add(credential)) <1>
.build();
return new InMemoryRelyingPartyRegistrationRepository(registration);
Expand Down Expand Up @@ -73,6 +74,10 @@ Also, your application can participate in an AP-initiated logout when the assert
3. Create, sign, and serialize a `<saml2:LogoutResponse>` based on the xref:servlet/saml2/login/overview.adoc#servlet-saml2login-relyingpartyregistration[`RelyingPartyRegistration`] associated with the just logged-out user
4. Send a redirect or post to the asserting party based on the xref:servlet/saml2/login/overview.adoc#servlet-saml2login-relyingpartyregistration[`RelyingPartyRegistration`]

NOTE: Adding `saml2Logout` adds the capability for logout to the service provider.
Because it is an optional capability, you need to enable it for each individual `RelyingPartyRegistration`.
You can do this by setting the `RelyingPartyRegistration.Builder#singleLogoutServiceLocation` property.

== Configuring Logout Endpoints

There are three behaviors that can be triggered by different endpoints:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1014,7 +1014,7 @@ public static final class Builder {

private Saml2MessageBinding assertionConsumerServiceBinding = Saml2MessageBinding.POST;

private String singleLogoutServiceLocation = "{baseUrl}/logout/saml2/slo";
private String singleLogoutServiceLocation;

private String singleLogoutServiceResponseLocation;

Expand Down

0 comments on commit 20c2529

Please sign in to comment.