TODO A list of pending things to do or pending questions to answer Should we delete/ignore the returnUrl (during authentication) when it points to /logout or /auth/session/refresh?