[JIRA] (IDP-1904) Additional policy rules for attribute filter

Scott Cantor (Jira) jira at shibboleth.atlassian.net
Thu Feb 10 13:20:03 UTC 2022


Scott Cantor ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A5b78efc9-1379-42cc-a3f6-56c6ea3a0007 ) *commented* on IDP-1904 ( https://shibboleth.atlassian.net/browse/IDP-1904?atlOrigin=eyJpIjoiZjRhYjE1MTRlNDY0NDk4YjhhNDQ3ZTFmYzM3MDEwMGQiLCJwIjoiaiJ9 )

Re: Additional policy rules for attribute filter ( https://shibboleth.atlassian.net/browse/IDP-1904?atlOrigin=eyJpIjoiZjRhYjE1MTRlNDY0NDk4YjhhNDQ3ZTFmYzM3MDEwMGQiLCJwIjoiaiJ9 )

I ended up (for now) deciding to revert to identifying the OAuth client as the Requester and I populated the resource server as a ProxiedRequester. I don’t entirely love that, but I did it because in OIDC it’s clearly the client doing the requesting, and if we suddenly changed that same pattern in a 4 legged OAuth case to swap the roles, it would seem pretty odd.

But just from the experience I went through dealing with all of this, we definitely don’t want to bake in an assumption that the RelyingPartyContext is where it normally is. So either we inject a strategy like we did for the ProxiedRequester lookup, or we just add a flag to AttributeFilterContext as an input. That seems a lot simpler to me.

( https://shibboleth.atlassian.net/browse/IDP-1904#add-comment?atlOrigin=eyJpIjoiZjRhYjE1MTRlNDY0NDk4YjhhNDQ3ZTFmYzM3MDEwMGQiLCJwIjoiaiJ9 ) Add Comment ( https://shibboleth.atlassian.net/browse/IDP-1904#add-comment?atlOrigin=eyJpIjoiZjRhYjE1MTRlNDY0NDk4YjhhNDQ3ZTFmYzM3MDEwMGQiLCJwIjoiaiJ9 )

Get Jira notifications on your phone! Download the Jira Cloud app for Android ( https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail ) or iOS ( https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100191- sha1:8f89d94 )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/commits/attachments/20220210/62cea62e/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-avatar-cc022209-c238-4316-bc70-293c2e3456c4
Type: image/png
Size: 341 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220210/62cea62e/attachment-0003.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-comment-icon-ddcc6bcb-575b-4ded-85c1-e3341e245d2a
Type: image/png
Size: 1084 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220210/62cea62e/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-footer-desktop-logo-98e27c9c-b4c7-4892-9780-533553f9322c
Type: image/png
Size: 10805 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220210/62cea62e/attachment-0005.png>


More information about the commits mailing list