SSO problems and doubts

Keep things simple.
Forget about iframes and implement standard federation with OIDC using the Authorization Code flow with PKCE.
Then, for logout, there are several options depending on the user experience and the type of application you have.

  • OIDC RP-Initiated Logout [1]
  • OIDC Back-Channel Logout [2]

[1] Final: OpenID Connect RP-Initiated Logout 1.0
[2] Final: OpenID Connect Back-Channel Logout 1.0