SSO logout with an embedded editor: which sessions actually end?
Identify separate session lifetimes and verify what logout, account switching, and access revocation actually terminate.

Logging out of the host application may leave an identity-provider session, an editor session, or a signed storage link valid. Inventory those credentials and define the intended outcome for each. Then test active tabs and account switching, not only whether the main page redirects to login.
Inventory independent credentials
List the identity provider session, application session, embedded editor credentials, storage links, and any background job authorization. Record who issues each credential, where it is stored, its lifetime, and its supported revocation mechanism. Browser cookies, bearer tokens, and server mappings behave differently. Avoid assuming that deleting one cookie invalidates every credential already issued during the session. Include refresh mechanisms and additional tabs, because a background refresh or another open document can recreate access that appeared to end in the tab where logout was clicked.
| Credential | Logout question |
|---|---|
| Application session | Can it authorize another host request? |
| Identity-provider session | Can it silently sign the user back in? |
| Editor session | Can an existing frame continue its permitted actions? |
| Storage link | Does independent expiry or revocation still govern retrieval? |
Choose the user-facing message from the observed result. “Signed out of this application” may be accurate when the identity provider intentionally remains signed in. “All document access ended” requires much broader evidence and may be incompatible with previously issued credentials. Use the authentication provider's supported logout mechanism rather than trying to delete cookies belonging to another origin.
Account switching deserves a separate test because a new session can look healthy while stale document state remains in a frame. Recreate embedded state when identity or tenant changes. Check browser back navigation and application caches for old document names as well as open content. The goal is to prevent a previous user's authorization context from becoming part of the next user's session.

Decide what happens to pending work
Decide whether application logout should end only the local application session or also initiate identity provider logout where supported. Define what happens to open documents, pending saves, and later callbacks. A callback representing previously authorized work may need separate treatment from a new interactive request. State the policy before wiring endpoints together. The system should neither discard accepted work accidentally nor permit new user operations indefinitely after logout. Any limitation imposed by the editor's session model should become an explicit acceptance condition rather than a hidden assumption.
Account switching can inherit stale document state
A shared browser may switch from one employee to another without restarting every frame or clearing every application cache. Ensure the new account cannot inherit the previous user's document view, permissions, or cached metadata. Key session state to the authenticated identity and tenant, and recreate embedded contexts when that identity changes. Review browser history and back navigation behavior as part of the experience. Sensitive content already displayed cannot be made unseen, but the application can prevent stale state from becoming a newly authorized session for another account.
Session acceptance checks
- Document logout effects separately for application, identity provider, editor, and storage credentials.
- Verify account switching with multiple tabs and cached application state.
- Preserve or reject pending work according to a documented save policy.
- Use secure cookie and token storage practices appropriate to each component.
- Retest session boundaries after authentication or editor upgrades.
Log out with two documents still open
Open two test documents in separate tabs, begin a harmless edit, and log out from the host application. Attempt a new open, an edit in the remaining tab, an export, and a direct download with a previously issued link. Then sign in as a different test account and use browser back navigation. Record immediate behavior and behavior after the documented credential lifetime. This scenario reveals which boundaries actively revoke access and which depend on expiry, giving administrators an evidence based description of the actual logout window.



