The OpenID Connect authentication support in Spotfire 7.8 doesnt come with the ability to communicate Logout/Token expiration back to Parent application. In a single sign-on scenario where the user authentication is initiated by an external application, Spotfire should relay the information about user inactivity/logout/session end to the external application, allowing for single logout. The specification for building this feature is documented at: http://openid.net/specs/openid-connect-session-1_0.html
Implemented in | 11.0 |
Spotfire 11.0 adds the ability to participate in Single Logout.
Spotfire can relay the information about user logout to the external application and act on such information from the external application, allowing for Single Logout (SLO).
The following three forms of SLO are supported:
RP-initiated Logout. See the OIDC draft for more details.
Front-Channel Logout. See the OIDC draft for more details.
Back-Channel Logout. See the OIDC draft for more details.
Please read more at: https://community.tibco.com/wiki/whats-new-tibco-spotfirer-110