Hi, Mike.
What do you think about making this behaviour default? Because doing logoff by default seems to be a more secure way (and default settings should be secure) + it doesn't require you to close-and-reopen window if you want to de-authenticate from the broker (and switch to other sessions). I think it would be a good idea, especially if this session broker system is mainly aimed at setups with thin clients (less configuration changes for main use-case).