# Question about behavior with SSO

**URL:** https://meta.discourse.org/t/question-about-behavior-with-sso/92664
**Category:** Support
**Created:** [July 18, 2018, 6:28pm UTC](https://meta.discourse.org/t/question-about-behavior-with-sso/92664 "2018-07-18T18:28:23Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![viethoang](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/viethoang/32/119620_2.png) [@viethoang](https://meta.discourse.org/u/viethoang)
#### Post date: [July 18, 2018, 6:28pm UTC](https://meta.discourse.org/t/question-about-behavior-with-sso/92664/1 "2018-07-18T18:28:23Z")

</div>

Context:

> **[Changing password on WaniKani does not invalidate forum session](https://community.wanikani.com/t/changing-password-on-wanikani-does-not-invalidate-forum-session/31835)**
>
> I changed my WaniKani password on another computer, while I was logged into the service on this machine. Now, I notice that, although my https://wanikani.com session has been invalidated on this computer (as I expected it to happen), the forum...

Our Discourse board is set up to use SSO with our application’s authentication, with registration disabled on the Discourse end. A user reported they reset their password on one machine. Used a different machine where they saw their session invalidated with our application (correct behavior), but their session with the Discourse board is still active (not ideal).

Is this the expected behavior given the scenario?

My first instinct is to do an SSO sign out payload to our Discourse board when the user updates their password on our application’s authentication. Just want to make sure if this is the path we need to take before I assign time onto this task.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [July 19, 2018, 4:39am UTC](https://meta.discourse.org/t/question-about-behavior-with-sso/92664/2 "2018-07-19T04:39:17Z")

</div>

> [@viethoang](#):
>
> do an SSO sign out payload to our Discourse board when the user updates their password on our application’s authentication

This definitely sounds correct to me.

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [August 18, 2018, 4:39am UTC](https://meta.discourse.org/t/question-about-behavior-with-sso/92664/3 "2018-08-18T04:39:20Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
