Revokes the SAML refresh token if present, clears the refresh token cookie, sets the Clear-Site-Data header so the browser clears cookies/storage/cache, and redirects to the frontend login page. Optional orgId query parameter is passed through to the login URL.