<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
#email-body { min-width: 30em !important; }
#email-page { padding: 8px !important; }
#email-banner { padding: 8px 8px 0 8px !important; }
#email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
#email-fields { padding: 0 8px 8px 8px !important; }
#email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
<tr valign="top">
<td id="email-page" style="padding:16px !important;">
<table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
<tr valign="top">
<td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
</tr><tr valign="top">
<td id="email-banner" style="padding:32px 32px 0 32px;">
<table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
<img id="email-avatar" src="https://issues.shibboleth.net/jira/secure/useravatar?avatarId=10203" alt="" height="48" width="48" border="0" align="left" style="padding:0;margin: 0 16px 16px 0;" />
<div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
<a class="user-hover" rel="tzeller@shibboleth.net" id="email_tzeller@shibboleth.net" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=tzeller%40shibboleth.net" style="color:#326ca6;">Tom Zeller</a>
commented on <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/bug.png" height="16" width="16" border="0" align="absmiddle" alt="Bug"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-616'>IDP-616</a>
</div>
<div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
<a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-616'><strong>lack of active changes to consent causes premature expiry and re-prompting</strong></a>
</div>
</td>
</tr>
</table>
</td>
</tr>
<tr valign="top">
<td id="email-fields" style="padding:0 32px 32px 32px;">
<table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
<tr valign="top">
<td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
<td>
<table border="0" cellpadding="0" cellspacing="0" width="100%">
<tr valign="top">
<td colspan="2" style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 16px 0;width:100%;">
<div class="comment-block" style="background-color:#edf5ff;border:1px solid #dddddd;color:#000000;padding:12px;"><p>As Scott suggested on the dev call, one way to update the consent cookie at every execution of the SSO flow is by using a mechanism I had been working on to purge storage records based on frequency of use. The UpdateCounter action stores an incrementing counter to determine the frequency of use of SPs. A corresponding function can be injected to use the counter when purging storage records, but at least the UpdateCounter action could keep the consent cookie as current as possible.</p>
<p>To enable the UpdateCounter action :</p>
<p>Add to <tt>system/flows/intercept/attribute-release-flow.xml</tt> :</p>
<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-xml"><span class="code-tag"><action-state id=<span class="code-quote">"AttributeConsentSetup"</span>></span>
...
<span class="code-tag"><evaluate expression=<span class="code-quote">"UpdateCounter"</span> /></span>
...
<span class="code-tag"></action-state></span>
</pre>
</div></div>
<p>Add to <tt>system/flows/intercept/attribute-release-beans.xml</tt> :</p>
<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-xml"><bean
id=<span class="code-quote">"UpdateCounter"</span>
scope=<span class="code-quote">"prototype"</span>
class=<span class="code-quote">"net.shibboleth.idp.consent.flow.storage.UpdateCounter"</span>
p:storageKeyLookupStrategy-ref=<span class="code-quote">"shibboleth.consent.UserAndRelyingPartyCounterStorageKey"</span> />
<!--
Function to return the storage key of the record used to count the number of times
the flow has executed.
-->
<bean
id=<span class="code-quote">"shibboleth.consent.UserAndRelyingPartyCounterStorageKey"</span>
class=<span class="code-quote">"net.shibboleth.idp.consent.logic.JoinFunction"</span>
c:functionA-ref=<span class="code-quote">"shibboleth.consent.UserAndRelyingPartyStorageKey"</span> >
<span class="code-tag"><constructor-arg name=<span class="code-quote">"functionB"</span>></span>
<span class="code-tag"><bean class=<span class="code-quote">"com.google.common.base.Functions"</span> factory-method=<span class="code-quote">"constant"</span>></span>
<span class="code-tag"><constructor-arg></span>
<span class="code-tag"><util:constant static-field=<span class="code-quote">"net.shibboleth.idp.consent.flow.storage.UpdateCounter.COUNTER_KEY"</span> /></span>
<span class="code-tag"></constructor-arg></span>
<span class="code-tag"></bean></span>
<span class="code-tag"></constructor-arg></span>
<span class="code-tag"></bean></span>
</pre>
</div></div>
<p>Obviously, modifying files in <tt>system/</tt> is a no-go, but this could be one way to resolve the issue.</p>
<p>Ian, maybe you could give this a try.</p>
<p>I'll comment again with the XML mods to enable the purging of storage records based on this counter.</p></div>
<div style="color:#505050;padding:4px 0 0 0;"> </div>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td><!-- End #email-page -->
</tr>
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
This message is automatically generated by JIRA.<br />
If you think it was sent incorrectly, please contact your JIRA administrators<br />
For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
</td>
</tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->