Re: [OAUTH-WG] What Does Logout Mean?

2018-03-31 Thread Phil Hunt
These kinds of discussions are why i think the signal should just be token revoked. It is up to the receiver to infer meaning. As soon as we talk in forma like commands(user is to be logged out), a standardized meaning becomes a problem. Receiver decision on action based on an issuer signal i

Re: [OAUTH-WG] What Does Logout Mean?

2018-03-31 Thread Bill Burke
On Fri, Mar 30, 2018 at 2:47 PM, Richard Backman, Annabelle wrote: > It sounds like you're asking the OP to provide client-side session management > as a service. There may be value in standardizing that, but I think it goes > beyond what Backchannel Logout is intended to do. Sure, sort of. Th