<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
#email-body { min-width: 30em !important; }
#email-page { padding: 8px !important; }
#email-banner { padding: 8px 8px 0 8px !important; }
#email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
#email-fields { padding: 0 8px 8px 8px !important; }
#email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
<tr valign="top">
<td id="email-page" style="padding:16px !important;">
<table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
<tr valign="top">
<td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
</tr><tr valign="top">
<td id="email-banner" style="padding:32px 32px 0 32px;">
<table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
<img id="email-avatar" src="https://issues.shibboleth.net/jira/secure/useravatar?avatarId=10202" alt="" height="48" width="48" border="0" align="left" style="padding:0;margin: 0 16px 16px 0;" />
<div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
<a class="user-hover" rel="vme28@canterbury.ac.nz" id="email_vme28@canterbury.ac.nz" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=vme28%40canterbury.ac.nz" style="color:#326ca6;">Vladimir Mencl</a>
created <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/improvement.png" height="16" width="16" border="0" align="absmiddle" alt="Improvement"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-624'>IDP-624</a>
</div>
<div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
<a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-624'><strong>Missing support for ordering attributes on consent screen</strong></a>
</div>
</td>
</tr>
</table>
</td>
</tr>
<tr valign="top">
<td id="email-fields" style="padding:0 32px 32px 32px;">
<table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
<tr valign="top">
<td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
<td>
<table border="0" cellpadding="0" cellspacing="0" width="100%">
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Issue Type:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/improvement.png" height="16" width="16" border="0" align="absmiddle" alt="Improvement"> Improvement
</td>
</tr> <tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Affects Versions:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
3.0.0 </td>
</tr>
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Assignee:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<a class="user-hover" rel="tzeller@shibboleth.net" id="email_tzeller@shibboleth.net" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=tzeller%40shibboleth.net" style="color:#326ca6;">Tom Zeller</a>
</td>
</tr> <tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Components:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
Attribute Consent, Attribute Resolver </td>
</tr>
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Created:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
24/Feb/15 10:30 PM
</td>
</tr> <tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Description:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<p style='margin-top:0;margin-bottom:10px;'>Hi,</p>
<p style='margin-top:0;margin-bottom:10px;'>In our IdPV2 deployments with uApprove, we have been setting the attribute order by whitelisting all attribute in the desired order.</p>
<p style='margin-top:0;margin-bottom:10px;'>We see this as critical for the user experience to group attributes together on the consent screen (e.g., commonName, displayName, givenName and surname are all together).</p>
<p style='margin-top:0;margin-bottom:10px;'>In IdPV3, there is no way to set the attribute order. The attributes appear in a "random" order - that does not change with a reload of the screen but does change if the set of attributes changes.</p>
<p style='margin-top:0;margin-bottom:10px;'>The rendering is done by a Velocity template (views/intercept/attribute-release.vm) that only iterates over the Map it receives.</p>
<p style='margin-top:0;margin-bottom:10px;'>The Map is a LinkedHashMap that should be preserving order. I tried digging through the code to see where it comes from, but could not find it.</p>
<p style='margin-top:0;margin-bottom:10px;'>I see one option for this as consistently using order-preserving Sets/Maps across the whole code, and then perhaps order could be determined by the order in which the attributes are listed in attribute-resolver.xml.</p>
<p style='margin-top:0;margin-bottom:10px;'>Alternatively, this is what I did as a workaround:</p>
<ul>
        <li>Add a new property to <tt>conf/idp.properties</tt> listing all defined attributes in the preferred order:
<div class="preformatted panel" style="border-width: 1px;"><div class="preformattedContent panelContent">
<pre># If not set, attributes would be listed in undefined order (as provided by the IdP)
# WARNING: attributes not listed here will be hidden from the consenting view
idp.consent.attributeOrder=commonName,displayName,auEduPersonLegalName,givenName,surname,email,\
eduPersonPrincipalName,uid,auEduPersonSharedToken,eduPersonTargetedID,eduPersonEntitlement,\
eduPersonAssurance,eduPersonAffiliation,eduPersonScopedAffiliation,eduPersonPrimaryAffiliation,\
auEduPersonAffiliation,organizationName,homeOrganization,homeOrganizationType,organizationalUnit,\
postalAddress,telephoneNumber,mobileNumber
</pre>
</div></div>
<p style='margin-top:0;margin-bottom:10px;'>And then modifying attribute-release.vm to use this property as the preferred order:</p>
<div class="preformatted panel" style="border-width: 1px;"><div class="preformattedContent panelContent">
<pre>--- attribute-release.vm        2015-02-18 12:06:09.504157844 +1300
+++ /opt/shibboleth-idp/edit-views/intercept/attribute-release.vm.attrlist        2015-02-25 16:16:49.576253157 +1300
@@ -71,7 +71,16 @@
</tr>
</thead>
<tbody>
- #foreach ($attribute in $attributeReleaseContext.getConsentableAttributes().values())
+ #set ($attributeOrder = $environment.getProperty("idp.consent.attributeOrder") )
+ #set ($consentableAttributes = $attributeReleaseContext.getConsentableAttributes() )
+                         #if ( $attributeOrder )
+                         #set ($allAttributeKeys = $attributeOrder.split(",") )
+                 #else
+                         #set ($allAttributeKeys = $consentableAttributes.keySet())
+                         #end
+ #foreach ($attributeKey in $allAttributeKeys)
+ #if ($consentableAttributes.get($attributeKey))
+ #set ($attribute = $consentableAttributes.get($attributeKey))
<tr>
<td>$encoder.encodeForHTML($attributeDisplayNameFunction.apply($attribute))</td>
<td>
@@ -90,6 +99,7 @@
</td>
</tr>
#end
+ #end
</tbody>
</table>
</div>
</pre>
</div></div>
<p style='margin-top:0;margin-bottom:10px;'>The code filters out attributes specified in the property but not in the current context, but does not render attributes that were not listed in the property.</p></li>
</ul>
<p style='margin-top:0;margin-bottom:10px;'>I was trying to append the entries from consentableAttributes.keySet() that are not in the ordered list at the end, but my Velocity-fu is not good enough for that (totally new to Velocity and guessing on the syntax).</p>
<p style='margin-top:0;margin-bottom:10px;'>Would this be worth adding for the next release - some option of setting the attribute order?</p>
<p style='margin-top:0;margin-bottom:10px;'>Cheers,<br/>
Vlad</p>
</td>
</tr>
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Environment:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<p style='margin-top:0;margin-bottom:10px;'>3.0.0 with LDAP and static connectors</p>
</td>
</tr>
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Project:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<a style="color:#326ca6;" href="https://issues.shibboleth.net/jira/browse/IDP">Identity Provider</a>
</td>
</tr> <tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Priority:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<img src="https://issues.shibboleth.net/jira/images/icons/priorities/major.png" height="16" width="16" border="0" align="absmiddle" alt="Major"> Major
</td>
</tr>
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Reporter:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<a class="user-hover" rel="vme28@canterbury.ac.nz" id="email_vme28@canterbury.ac.nz" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=vme28%40canterbury.ac.nz" style="color:#326ca6;">Vladimir Mencl</a>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td><!-- End #email-page -->
</tr>
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
This message is automatically generated by JIRA.<br />
If you think it was sent incorrectly, please contact your JIRA administrators<br />
For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
</td>
</tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->