-
Suggestion
-
Resolution: Unresolved
-
None
-
6
-
Issue Summary
When a user session is over due to a logout, sometimes the session is still alive on IDP, and the user is not prompted for a new authentication. Send the prompt=login or ForceAuthn=true will force a reauthentication no matter what.
It will be nice to have a parameter to control this behavior.
Steps to Reproduce
- Login in the Bitbucket using an IDP
- Logout of it
- Try to login back in, the user is automatically authenticated
Expected Results
The user needs to provide a username and password manually again.
Actual Results
The user login to the system automatically
Workaround
Currently, there is no known workaround for this behavior. A workaround will be added here when available.
- relates to
-
ACCESS-592 Logging out of Atlassian account does not log out of SAML provider
- In Progress
- is action for
-
ENT-555 Failed to load
- mentioned in
-
Page Failed to load
[ACCESS-1655] Add a possibilty to send to IDP the prompt=login/ForceAuthn=true when the user logout
Support reference count | Original: 5 | New: 6 |
Support reference count | Original: 4 | New: 5 |
Support reference count | Original: 3 | New: 4 |
Remote Link | New: This issue links to "Page (Confluence)" [ 924472 ] |
Remote Link | Original: This issue links to "ENT-555 (Jira)" [ 915383 ] | New: This issue links to "ENT-555 (Hello Jira)" [ 915383 ] |
Remote Link | New: This issue links to "ENT-555 (Jira)" [ 915383 ] |
Support reference count | Original: 2 | New: 3 |
Support reference count | Original: 1 | New: 2 |
This is also important for users using multiple accounts and wanting to switch between those accounts. Currently when manually logged out of Atlassian Cloud, the user remains logged in in the IdP so upon subsequent login attempt to Atlassian Cloud the user is logged in again as the same user, where the goal of the user was to switch to a different (IdP) account.