OFBiz is made up of several web applications.
To allow the user to sign in only once, a unique token value is presented for verification each time the user navigates to an unvisited web application.
I propose to add CAS SSO server as a component to OFBiz framework, and to use it as a basis for OFBiz SSO solution.
This new approach will allow us to use AJAX to update content partially, without invalidating the menu links.
CAS is now Apache-licensed. See
https://www.apereo.org/projects/cas