Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-1655

Add a possibilty to send to IDP the prompt=login/ForceAuthn=true when the user logout

    • 6
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Issue Summary

      When a user session is over due to a logout, sometimes the session is still alive on IDP, and the user is not prompted for a new authentication. Send the prompt=login or ForceAuthn=true will force a reauthentication no matter what.

      It will be nice to have a parameter to control this behavior. 

      Steps to Reproduce

      1. Login in the Bitbucket using an IDP
      2. Logout of it
      3. Try to login back in, the user is automatically authenticated

      Expected Results

      The user needs to provide a username and password manually again.

      Actual Results

      The user login to the system automatically

      Workaround

      Currently, there is no known workaround for this behavior. A workaround will be added here when available.

          Form Name

            [ACCESS-1655] Add a possibilty to send to IDP the prompt=login/ForceAuthn=true when the user logout

              Unassigned Unassigned
              6eec25a24f71 Diego Martins (Inactive)
              Votes:
              10 Vote for this issue
              Watchers:
              12 Start watching this issue

                Created:
                Updated: