<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
#email-body { min-width: 30em !important; }
#email-page { padding: 8px !important; }
#email-banner { padding: 8px 8px 0 8px !important; }
#email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
#email-fields { padding: 0 8px 8px 8px !important; }
#email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
<tr valign="top">
<td id="email-page" style="padding:16px !important;">
<table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
<tr valign="top">
<td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
</tr><tr valign="top">
<td id="email-banner" style="padding:32px 32px 0 32px;">
<table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
<img id="email-avatar" src="https://issues.shibboleth.net/jira/secure/useravatar?avatarId=10202" alt="" height="48" width="48" border="0" align="left" style="padding:0;margin: 0 16px 16px 0;" />
<div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
<a class="user-hover" rel="putmanb@shibboleth.net" id="email_putmanb@shibboleth.net" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=putmanb%40shibboleth.net" style="color:#326ca6;">Brent Putman</a>
commented on <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/subtask_alternate.png" height="16" width="16" border="0" align="absmiddle" alt="Sub-task"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-302'>IDP-302</a>
</div>
<div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
<a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-302'><strong>Verify and document proposed metadata provider work</strong></a>
</div>
</td>
</tr>
</table>
</td>
</tr>
<tr valign="top">
<td id="email-fields" style="padding:0 32px 32px 32px;">
<table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
<tr valign="top">
<td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
<td>
<table border="0" cellpadding="0" cellspacing="0" width="100%">
<tr valign="top">
<td colspan="2" style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 16px 0;width:100%;">
<div class="comment-block" style="background-color:#edf5ff;border:1px solid #dddddd;color:#000000;padding:12px;"><p>I had completely forgotten this issue was out there. My specific comments on the things Scott hasn't mentioned: </p>
<p>Merging of HTTP and Filebacked HTTP: I sort of see the value. Probably not that hard to do, but also doesn't seem like a high priority.</p>
<p>More stringent data checks: I see the value. Easy to do with a filter, so easy to add later. Not sure about the enforced "always on" part.</p>
<p>Inputs to signature validation filter: I'd see this as done either 1) in the custom parsing code in the IdP (legacy), or 2) via a Spring FactoryBean (new Spring-native style), taking those inputs and producing a TrustEngine impl. Not hard, but low priority.</p>
<p>Performance metrics: useful, but pretty invasive. Unless we used some sort of AOP type of approach to time methods.</p>
<p>KeyInfo stuff: We decided not to literally what Chad said, but the general problem has been handled in a different way. So this one's already "done".</p>
<p>Detecting multiple entityIDs: Within a given metadata provider, we now already log a WARN when a duplicate is detected. Detecting this is easy now, it's a natural outcome of the way we pre-process and store the metadata essentially as a Map<String, List<EntityDescriptor>>. This is pretty isolated to one method in AbstractMetadataResolver. We could in theory do something there based on some config flag(s). Still not sure about the viability of detecting duplicates across multiple providers in a chain or composite provider as I noted in <a href="https://issues.shibboleth.net/jira/browse/IDP-299" title="Finish CompositeMetadataResolver and relocate to OpenSAML">IDP-299</a> - I infer that was probably the main case Chad wanted to deal with, since it's unlikely a EntitiesDescriptor batch would have duplicates, unless the federation or publisher isn't doing their job.</p>
</div>
<div style="color:#505050;padding:4px 0 0 0;"> </div>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td><!-- End #email-page -->
</tr>
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
This message is automatically generated by JIRA.<br />
If you think it was sent incorrectly, please contact your JIRA administrators<br />
For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
</td>
</tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->