Description
PROBLEM STATEMENT:
During knox global logout , SSO token should be either disabled or removed
BUILDS:
2.0
STEPS TO REPRODUCE:
- Enable logout "knox.homepage.logout.enabled" , configure "knox.global.logout.page.url" to "https://*********"
- Access knox home page
- Click on global logout
CURRENT BEHAVIOUR:
the session will be removed and user if need to access knox home page again should relogin , but still the previous SSO token will be alive for default 1 day which can cause security risk
EXPECTED BEHAVIOUR:
During knox global logout , the corresponding SSO token should be either disabled or revoked
Attachments
Issue Links
- is caused by
-
KNOX-2961 KnoxSSO Token Invalidation
- Resolved
- links to