The /?logout=1 endpoint destroyed only the PWA's own PHP session and then
redirected to the bare landing page — which has no session and immediately
blocks access, so the user was never actually logged out of SSO.
- public/index.php: after session_destroy(), redirect to
https://lupmis4luspa.org/user-logout (the portal's full SSO logout) instead
of the landing page. Crucially, no longer clear sso_auth_token here —
/user-logout needs that cookie to identify which SSO session to terminate
(and it clears the cookie itself). The production access-guard bounce to the
landing page is unchanged.
- main.js: drop the now-redundant best-effort client call to /sso/logout; the
server redirect chain (/?logout=1 → /user-logout) owns the SSO logout. Offline
guard and district-cache wipe unchanged.
- sw.js: update the v12 changelog note (still v12; not yet deployed).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>