Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Spring Security SAML logout: local session versus single logout

Last updated: 1 Oct 20264 min read
tutorial
IntermediateBy AITrove Editorial

Local logout ends this application's session; SAML single logout exchanges signed protocol messages with the asserting party.

Decide which session ends

A dispatcher clicks Sign out. A local logout clears this service provider's authenticated session but can leave the identity-provider session active, allowing another login without a password prompt. SAML single logout can involve the asserting party and other service providers when the IdP supports it. Spring Security supports both relying-party and asserting-party initiated flows. Session ownership still determines what the application invalidates locally.

Configure the protocol as a pair

Single logout requires the asserting party to support it, compatible endpoints, and signing credentials on the relying party. The default SAML logout processing endpoint is /logout/saml2/slo. A changed endpoint must be reflected in both registration and IdP configuration. Keep a separate local-only endpoint if the product intentionally offers it; label its effect accurately.

Test both directions

Run an RP-initiated logout and inspect the signed request and response. Then initiate logout at the IdP and assert the local session stops authorizing requests. Also simulate an unavailable IdP: define whether the local session is cleared, whether retry is possible, and what the user sees.

Implementation sketch

Java
http.logout(local -> local.logoutUrl("/logout"))
    .saml2Logout(saml -> saml.logoutUrl("/saml2/logout"));

Cost and verification

Single logout adds signed XML exchanges, network latency and certificate maintenance. Local logout is cheaper but cannot promise termination of the IdP session.

Common Mistakes

  • Do not label local logout as logout from every federated application.
  • Do not enable single logout without IdP support and signing credentials.
  • Do not change the SAML logout endpoint only on the application side.

Read next

Spring Security SAML relying party: align registration, ACS and metadata, Spring SAML session revocation: closing the browser is not deprovisioning, Spring Security OAuth2 login: callback, identity and browser session.

spring
spring-boot
security
saml-local-vs-single-logout
Storage details