User story
As a user, I want to sign out of all the apps where I have used my federated identity.
Context of the story
I am a shift work in a warehouse, and sign into a couple web apps on my shared device in order to do my job. When I am done with my shift, I click "Sign out" in the app, and give the device to my coworker. I expect to be entirely signed out so that my coworker does not accidentally or maliciously manipulate data connected to me.
Should this be considered sanctioned or unsanctioned tracking?
Sanctioned.
Explicit list of parties involved
Each application that the user has signed into.
The IDP.
The User.
Complicating characteristics
This relies on Front channel logout: fedidcg/protocol-library#10
Additional information
The IdP must contact each application that I have signed into, to tell them that I have signed out.