http://openid.net/specs/openid-connect-session-1_0.html
They set up invisible iframes so that an app can query the auth server's
iframe to check to see if the login cookie is still set. Doesn't that
seem weird?
Was kind of hoping for a REST interface back to the application like we
currently have.
--
Bill Burke
JBoss, a division of Red Hat
http://bill.burkecentral.com