Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Odhlasovanie google / facebook #125

Open
tvinar opened this issue Feb 7, 2018 · 3 comments
Open

Odhlasovanie google / facebook #125

tvinar opened this issue Feb 7, 2018 · 3 comments

Comments

@tvinar
Copy link
Contributor

tvinar commented Feb 7, 2018

Pri prihlaseni cez google a facebook tlacitko odhlasenie len zrusi aktualnu session, no nepresmeruje na odhlasenie z prislusnej sluzby (co znamena, ze ak stlacim znovu tlacitko "Prihlasit cez Google", tak mi jednoducho nabehne uz prihlasena stranka a tiez pripadne ostatne sluzby ostanu potichu prihlasene). Sposobuje to problem na verejnych pocitacoch, ked si user mysli ze sa odhlasil ale ono v skutocnosti nie.

@mrshu
Copy link
Contributor

mrshu commented Feb 7, 2018

Ak tomu spravne chapem, tak v principe ide o to, ze ked sa clovek odhlasi z ePrihlasky, je tu iste ocakavanie, ze sa odhlasi aj zo sluzby, ktora bola pouzita na prihlasenie.

Toto vsak trochu naraza ako na realitu, tak aj na filozofiu OAuth autorizacie. Ta v principe iba bezpecnym sposobom ponuka odpoved na takuto otazku: Vie sa pouzivatel uspesne prihlasit u vas (teda Google/FB loginom)? Ak ano, dajte nam to vediet a my tohto pouzivatela prihlasime aj u nas. Ak je uz pouzivatel prihlaseny, nema asi uplne zmysel ukazovat mu znova login screen -- uz predsa je (na Google/FB) raz prihlaseny.

Po tom, ako toto prebehne sa pouzivatel moze kludne z Google/FB odhlasit -- ePrihlaska uz ma informaciu o tom, ze sa tam naozaj prihlasit dokaze. Prepojit odhlasenie z ePrihlasky s odhlasovanim pouzivatela z inej sluzby dava asi zmysel pri verejnych pocitacoch, ale pre ludi, ktori sa prihlasili z prehliadaca v ktorom tieto sluzby dlhodobejsie aktivne pouzivaju (i.e. napriklad GMail/Google Docs alebo Facebook) by to zrejme predstavovalo zasadne narusenie ich workflow.

Kompromisom v tomto pripade sa mi zda moznost pridat odhlasovaci link (ako je popisane napr. tu pre Google) pre jednotlive sluzby, ktory by sa ukazal po odhlaseni z ePrihlasky.

@tvinar
Copy link
Contributor Author

tvinar commented Feb 7, 2018 via email

@mrshu
Copy link
Contributor

mrshu commented Feb 7, 2018

Ok.

Nemam stale celkom jasno v tom, ako presne sa odhlasit z Facebooku, ale tu je k tomu nejake info: https://stackoverflow.com/questions/2764436/facebook-oauth-logout/9799430#9799430

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants