FAQ | This is a LIVE service | Changelog

Looking for documents about force re-authentication and logout

I am looking for any official/UIS documentation on (force) re-authentication and logout with shib SP/IdP, but I can't find them at https://docs.raven.cam.ac.uk/. Can you point me to where I can find any information about them?

(The problem I am facing is when a user tries to re-log in to a system, they are not redirected to Raven login page if a valid (either idp or webauth) session is present. This is benefitial for systems with high security requirements. I tried to log out IdP session (with the handler idp/profile/Logout), but it seems that it only clears out "shib-idp" session but not "ucam-session". The user can only be redirected to Raven login page unless all valid sessions are cleared out, i.e., SP, IdP (shib-idp and webauth) and Raven) from browser. Is there any other way to force user re-authentication (redirecting to Raven login page), other than clearing all sessions?)