You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ASWebAuthenticationSession时如何清除Cookie?

Fixing SSO Session Persistence on Shared Devices

Great question—this is a super common security pitfall when dealing with shared devices and single sign-on (SSO) setups! Let’s break down how to fix this both for end-users and if you’re working on the application side.

End-User Fix: Manually Clear SSO Cookies

If you’re a regular user hitting this issue, clearing the relevant browser cookies will force the next user to go through full SSO authentication again. Here are steps for the most popular browsers:

  • Chrome/Edge:
    1. Click the three-dot menu in the top-right → Select Settings
    2. Navigate to Privacy and Security (Chrome) or Privacy, Search, and Services (Edge)
    3. Click Clear browsing data
    4. Only check Cookies and other site data, set the time range to All time
    5. Click Clear data to finish
  • Firefox:
    1. Click the three-line menu in the top-right → Select Settings
    2. Switch to the Privacy & Security tab
    3. Under Cookies and Site Data, click Clear Data
    4. Check Cookies and Site Data and confirm the action

Developer Fixes to Prevent This Issue Long-Term

If you’re building or maintaining the application, you can address this root cause to avoid the problem entirely:

  • Enforce Short-Lived Session Cookies: Set SSO session cookies to expire after a short period of inactivity (e.g., 30 minutes) and avoid persistent "remember me" attributes. This ensures cookies auto-expire when the browser is closed.
  • Build a Proper Logout Flow: When a user logs out, don’t just clear your app’s session—call your SSO provider’s official logout endpoint (like OAuth 2.0’s logout route). This wipes the SSO provider’s authentication cookies from the browser, fully terminating the old user’s session.
  • Add a "Public Device" Prompt: On your login page, ask users "Is this a public/shared device?". If they select yes, set cookies as Session-only (they’ll delete when the browser closes) instead of persistent.
  • Secure Your Cookies: Mark all SSO-related cookies with HttpOnly, Secure, and SameSite=Strict flags. This boosts security, prevents cross-site session hijacking, and ensures cookies only travel over HTTPS.

Quick Note for Enterprise Environments

If this is an internal corporate SSO system, reach out to your IT team—many companies use device management tools (like group policies) to automatically clear cookies and session data on shared office devices, no manual action needed.

内容的提问来源于stack exchange,提问作者ragul ml

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 09:25:16