[JIRA] (IDP-1997) metadata driven configuration based on a list rather than a single value?

Liam Hoekenga (Jira) jira at shibboleth.atlassian.net
Wed Aug 24 19:12:47 UTC 2022


Liam Hoekenga ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3Acb0f0ab4-8d2d-447d-98fa-6250c50c368c ) *created* an issue

Identity Provider ( https://shibboleth.atlassian.net/browse/IDP?atlOrigin=eyJpIjoiOGMyNWZlNDkzNDM5NDQ4NDliYWY0NTk3ZDExZjU5NzUiLCJwIjoiaiJ9 ) / New Feature ( https://shibboleth.atlassian.net/browse/IDP-1997?atlOrigin=eyJpIjoiOGMyNWZlNDkzNDM5NDQ4NDliYWY0NTk3ZDExZjU5NzUiLCJwIjoiaiJ9 ) IDP-1997 ( https://shibboleth.atlassian.net/browse/IDP-1997?atlOrigin=eyJpIjoiOGMyNWZlNDkzNDM5NDQ4NDliYWY0NTk3ZDExZjU5NzUiLCJwIjoiaiJ9 ) metadata driven configuration based on a list rather than a single value? ( https://shibboleth.atlassian.net/browse/IDP-1997?atlOrigin=eyJpIjoiOGMyNWZlNDkzNDM5NDQ4NDliYWY0NTk3ZDExZjU5NzUiLCJwIjoiaiJ9 )

Issue Type: New Feature Affects Versions: 4.2.1 Assignee: Brent Putman ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A97de0981-adc3-4044-95ed-131622fad81e ) Components: Metadata Created: 24/Aug/22 3:12 PM Priority: Trivial Reporter: Liam Hoekenga ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3Acb0f0ab4-8d2d-447d-98fa-6250c50c368c )

We’ve been asked to update the context-check intercept with a rule that would deny access to services based on group membership.

It seems like we need to compare the list of groups that the user is a member of to the list of authorized groups for that service provider. I feel like the best place to store the list of authorized groups for a given service provider might be in the metadata for that provider.

I’m trying to envision what that might look like…. maybe a single tag with a value that contains a space separated list of entityIDs (like the relyingParties attribute that you can place on an attribute definition).
I’ve seen examples metadata driven configuration looking at a single value, but I’m not sure how we’d evaluate a single value that is actually a list of values?

If we follow the model relyingParties activation condition model (by which, I guess I actually mean “splitting space separated list into separate values that can be evaluated”), is there some existing glue that we could take advantage of?

( https://shibboleth.atlassian.net/browse/IDP-1997#add-comment?atlOrigin=eyJpIjoiOGMyNWZlNDkzNDM5NDQ4NDliYWY0NTk3ZDExZjU5NzUiLCJwIjoiaiJ9 ) Add Comment ( https://shibboleth.atlassian.net/browse/IDP-1997#add-comment?atlOrigin=eyJpIjoiOGMyNWZlNDkzNDM5NDQ4NDliYWY0NTk3ZDExZjU5NzUiLCJwIjoiaiJ9 )

Get Jira notifications on your phone! Download the Jira Cloud app for Android ( https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail ) or iOS ( https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100206- sha1:1c596f6 )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/commits/attachments/20220824/4c8bdbbe/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-avatar-8acef75d-5138-435a-aaf1-9da633fb82f1
Type: image/png
Size: 341 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220824/4c8bdbbe/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-comment-icon-9557cac1-a87f-4790-a70d-cf8a73dca7a3
Type: image/png
Size: 1084 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220824/4c8bdbbe/attachment-0005.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-trivial-a596d204-69f2-4e5f-a237-a71a7a7a4a87
Type: image/png
Size: 563 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220824/4c8bdbbe/attachment-0006.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-footer-desktop-logo-09686ab9-6478-4b42-80cf-6282dd38a3fa
Type: image/png
Size: 10805 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220824/4c8bdbbe/attachment-0007.png>


More information about the commits mailing list