Files
keycloak-pattern/docs/evidence/c1-multi-app-sso/README.md
T
DongHyeonkaandClaude Opus 5 e856e7af4d docs: C-1 — killing the SSO session logs nobody out
One user session carries a client session per application, so visiting the second app skips the login screen. Deleting the identity provider session leaves both application sessions untouched and both apps keep serving, because the identity provider, the application session and the access token each have their own lifetime.

That inverts the B-2 finding: there the app session was cleared and the surviving SSO session let the user straight back in. Either way, clearing one side leaves the other. It also means an identity provider outage is a single point of failure for logging in, not for already-authenticated users, and the failure arrives late and all at once.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-04 14:49:36 +09:00

1.4 KiB
Raw Blame History

C-1 — 다중 앱 SSO 증거

2026-09-04 16:1516:30 KST 해설: docs/experiment-c1-multi-app-sso.md

파일 무엇을 보여주는가
01-baseline.txt 초기화 시도 — logout-all 이 안 먹어 세션 4개가 남았다
02-after-app1-login.txt app1 로그인 후 — user session 1 · client session 1 · Redis 1 · DB 1행
03-after-app2-visit.txt app2 방문 후 client session 1 → 2, bff-confidentialoauth2-proxy 가 같은 user session 에 붙음. Redis 에 두 종류 세션
04-sso-session-killed.txt IdP 세션 삭제 후 — 앱 세션 셋 다 남아 있다. realm 을 join 해 보고서야 남은 것이 master 세션임을 확인
c1-sso-app2-no-login-screen.png app2 가 로그인 화면 없이 열린 화면
c1-apps-alive-after-idp-logout.png IdP 세션을 죽인 뒤에도 그대로 열리는 화면

핵심 세 줄

  1. SSO 는 user session 1개에 client session N개 구조다 — A-3(전체 소실)과 B-3(client 만 제거)의 차이가 여기서 의미를 갖는다.
  2. IdP 세션을 죽여도 두 앱은 계속 동작한다. 세 층(IdP·앱·토큰)의 수명이 각자이기 때문이다.
  3. IdP 는 "로그인 경로"의 단일 장애점이지 "이미 로그인한 사용자"의 단일 장애점이 아니다. 장애는 앱 세션 수명만큼 지연되어 몰려온다.