[JIRA] (JOIDCRP-35) Add support for passive inbound requests
Scott Cantor (Jira)
jira at shibboleth.atlassian.net
Mon Jun 5 13:32:32 UTC 2023
Scott Cantor ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A5b78efc9-1379-42cc-a3f6-56c6ea3a0007 ) *commented* on JOIDCRP-35 ( https://shibboleth.atlassian.net/browse/JOIDCRP-35?atlOrigin=eyJpIjoiYmMzYzRhMzhmNTRmNGY4MWEzNTlhN2ZmN2NhYTliMWEiLCJwIjoiaiJ9 )
Re: Add support for passive inbound requests ( https://shibboleth.atlassian.net/browse/JOIDCRP-35?atlOrigin=eyJpIjoiYmMzYzRhMzhmNTRmNGY4MWEzNTlhN2ZmN2NhYTliMWEiLCJwIjoiaiJ9 )
The disallowed features feature prevents SPs from signaling something in their request to “protect” the IdP’s behavior if something is already being set there. It doesn’t addressing the proxying issue, how to set certain values based on the underlying request. All the SAML features have proxying awareness built in to allow those signals to be copied from the original request. The defaults in most cases are to pass through settings when proxying, overriding the usual defaults.
The difference with IsPassive is that there’s no reason an IdP operator would ever try and force this at the IdP. Blocking it isn’t that important but my point was simply that there’s no reason to have a profile option for it.
Since there’s no setting, passive would always be copied along (as it must be), so the only control you get is to just prevent the original request from asking for it.
( https://shibboleth.atlassian.net/browse/JOIDCRP-35#add-comment?atlOrigin=eyJpIjoiYmMzYzRhMzhmNTRmNGY4MWEzNTlhN2ZmN2NhYTliMWEiLCJwIjoiaiJ9 ) Add Comment ( https://shibboleth.atlassian.net/browse/JOIDCRP-35#add-comment?atlOrigin=eyJpIjoiYmMzYzRhMzhmNTRmNGY4MWEzNTlhN2ZmN2NhYTliMWEiLCJwIjoiaiJ9 )
Get Jira notifications on your phone! Download the Jira Cloud app for Android ( https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail ) or iOS ( https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100225- sha1:4a1ccf9 )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/commits/attachments/20230605/de9efa32/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-avatar-3291e2c8-b097-4ef3-a6d9-750c103abe07
Type: image/png
Size: 302 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20230605/de9efa32/attachment-0003.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-comment-icon-5a3f55a0-6b25-4736-ad24-55c718dd87ec
Type: image/png
Size: 1084 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20230605/de9efa32/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-footer-desktop-logo-b290cfb9-6e3d-4d3d-bb12-19d5b234e103
Type: image/png
Size: 10805 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20230605/de9efa32/attachment-0005.png>
More information about the commits
mailing list