SAML会话管理与单点注销(SLO)相关技术问题咨询
Great question—let’s break this down clearly since SAML session behavior can feel a bit nuanced, especially when dealing with multiple browsers or devices.
IdP Session Behavior Across Browsers/Devices
Yes, your initial hunch is spot on: the IdP will create separate, independent sessions for each browser (or device) you use to log in. Here’s why:
- IdPs typically track user sessions using browser-specific storage mechanisms like cookies. Since browsers (e.g., Firefox vs. Chrome) don’t share cookie stores, each one gets its own unique session identifier from the IdP.
- Even on the same device, different browser profiles (like a regular Chrome window vs. an incognito Chrome window) will also trigger separate IdP sessions, as their storage is isolated.
- For different physical devices, the isolation is even more obvious—there’s no shared storage between your laptop and phone, so the IdP sees each login as a distinct user session.
How SLO Works in This Scenario
When an SP initiates a Single Logout (SLO) request, the scope of that logout is strictly limited to the current browser/device session that initiated it:
- The SLO request is sent from the browser where the user is currently logged into the SP. This request includes context tied to the IdP session for that specific browser.
- The IdP will then iterate through all SPs that are associated with that particular session and send logout requests to each of them.
- Any other sessions (whether in a different browser on the same device, or a browser on another device) remain completely unaffected. The IdP doesn’t link these separate sessions together by default, so it won’t trigger logout for them.
Verifying Your Understanding
Your conclusion is 100% correct:
- Logging into the same IdP via Firefox and Chrome creates two separate IdP sessions.
- If you initiate SLO from an app in Firefox, only the SP sessions tied to that Firefox-based IdP session will be logged out. Your Chrome sessions (and any other device sessions) will stay logged in as normal.
A quick side note: Some IdPs offer optional cross-device session management features (like allowing users to view and log out all active sessions from a dashboard), but this is an extra layer on top of the core SAML spec. By default, SAML follows the browser/device session isolation you’re describing.
内容的提问来源于stack exchange,提问作者user2802945

