Records on the session that it signed into a client, when an authorization response goes out.
Never throws: a bookkeeping failure must not stop a client getting its code.
the sign-on session
the client answered
Optional
iss and sub as the client's ID Token names them, which Back-Channel Logout needs later
iss
sub
Records on the session that it signed into a client, when an authorization response goes out.
Never throws: a bookkeeping failure must not stop a client getting its code.