Arguably, both sites should check for cookies if they require them, as it's possible for a user to reject cookies for each site independently. SSO should certainly perform its own check.
Arguably, both sites should check for cookies if they require them, as it's possible for a user to reject cookies for each site independently. SSO should certainly perform its own check.