Support Article
SAML timeout does not work for all links in the portal
SA-15726
Summary
A user session times out, based on authentication timeout specified in the access group record. If the user attempts to take an action in the application, the timeout activity is called successfully for some links (such as a link to a work object in the user's worklist), but it does not work for all application links (such as Work baskets). When this works successfully, the user is redirected to a specific URL mentioned on the SAML SLO. When this fails, the system re-routes to the different URL.
Error Messages
Not Applicable
Steps to Reproduce
1. Create a system with SAML authenticated user.
2. Update Standard Activity to set parameter of ProviderSLORedirectToIdP to different URL than home URL of IDP.
3. Customize show-HTML step to call custom HTML with alert.
4. Click Work -Object from Work List. It will call custom HTML.
5. Click other links in the Portal . It will reroute to home URL of IDP application.
Root Cause
The best practice to implement logging a user off when a timeout occurs is to use the pxSessionTimer with the logoff timer.
Resolution
Refer to SA-10027 for details on implementing the SessionTimer with a logoff timer.
http://pdn.pega.com/node/289991
Published January 31, 2016 - Updated October 8, 2020
Have a question? Get answers now.
Visit the Collaboration Center to ask questions, engage in discussions, share ideas, and help others.