OIDC Session Management
Description
OpenID Connect Session Management settings according to the OpenID Connect Session Management Specification
May be used by
Properties
Same Site Policy (
sameSitePolicy) Description
Specifies the 'SameSite' cookie attribute of the OP User Agent State cookie.
The correct choice of this property is essential for the correct operation of this feature:
- For same-domain scenarios, 'Lax' should be chosen. In this case, the cookie will only be accessible when the top-level page (which includes the OP iframe) is in the same domain as the OP iframe)
- For cross-domain scenarios, 'None' must be chosen. In this case, 'Secure' is also automatically appended because modern browsers only accept those cookies on a secure connection
- To rely on browser default behavior (not recommended), 'No SameSite Attribute' can be chosen, resulting in cookies usually interpreted as 'Lax' depending on the browser version.
Attributes
Enum
Optional
Default value
LAX
Debug (
debug) Description
When enabled, the OP Iframe writes debug logs to the browser console on every message, allowing to debug the functionality and find the reason for a possible 'error' response. In addition, the origin check endpoint logs a debug log when an origin is not accepted with further information.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)
type: OpenIDConnectSessionManagement
id: OpenIDConnectSessionManagement-xxxxxx
displayName:
comment:
properties:
debug: false
sameSitePolicy: LAX