-
Notifications
You must be signed in to change notification settings - Fork 350
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Implement multiple concurrent sessions #34
Comments
We created an application that supports multiple identities. This seems to work pretty well. A user signs in as Foo at our single instance of identity server and then can access our backend APIs. Then, the user also signs in as Bar to access our APIs under this identity. Our client apps (mobile, web, web extension) allow the user to switch between identity Foo and Bar. The apps maintain the access token for each identity such that the right access token is used when accessing the backend APIs. Also, refresh tokens work fine. As far as we can see, the only thing that is not working is signout. This is because for signout the session cookie is used to identify the user. However, this cookie always contains the information of the last session (the session of Bar in my example). So, when signing out Foo, actually Bar is signed out. I think this is a known issue because simultaneous sessions are not supported (yet). My question is twofold:
Thanks for your help. |
Some research notes. This all looks mostly doable today with all our extensibility points, but intimate knowledge and understanding of how things work is necessary. The things that need to be done are:
So technically all possible today with enough effort. It'd be nice as a first class feature. I don't think we have time for 6.0, but possibly for v6.x (don't know if breaking changes would be required, which would push it to v7). |
Hi, are there any updates regarding this feature? |
Given that it seems possible today with existing extensibility points, we've not been focused on this feature. |
Hi, I am trying to get this to work on IS 6.x. Is there an example on how to realize this feature? |
Sorry, we don't have an official sample of this feature. |
Any progress on this one or at least did someone (maybe you @thomas-bingel) manage to implement it using current extensibility points? |
Nothing new to report. After each release we review all issues in the future milestone, so watch this for any changes. |
It is looking like our org and numerous products will need this functionality as well. I'll probably be diving into it soon and exploring how we might be able to achieve this with current Duende extensibility points. Our goal is very similar to how Google provides multiple active sessions and allows you to switch between applications within each user session context. Will try to remember to report back here any findings that might be useful to others. |
See also DuendeSoftware/Support#593: If I can contribute, just let me know. I can for instance share the code for the session cookie with a collection of authentication tickets. |
Our application needs this functionality as well. I am just wondering whether expressing interest from the community here will influence the priority in the backlog. :) |
We'd be up for this feature also! |
Hi, we are also facing the same issue with sessions: we store them server-side and if the same user is authenticated in two different browsers even with different |
@merijndejonge we are looking into something similar. Would any of your code/some examples of it happen to be available somewhere online? |
We would also interested in this feature! |
migrated from IdentityServer4
IdentityServer/IdentityServer4#1721
The text was updated successfully, but these errors were encountered: