<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
    #email-body { min-width: 30em !important; }
    #email-page { padding: 8px !important; }
    #email-banner { padding: 8px 8px 0 8px !important; }
    #email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
    #email-fields { padding: 0 8px 8px 8px !important; }
    #email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
    <tr valign="top">
        <td id="email-page" style="padding:16px !important;">
            <table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
                <tr valign="top">
                    <td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
                </tr><tr valign="top">
    <td id="email-banner" style="padding:32px 32px 0 32px;">

                
        
        
            <table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
    <tr valign="top">
        <td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
                                        <img id="email-avatar" src="https://issues.shibboleth.net/jira/secure/useravatar?ownerId=rdw%40iay.org.uk&avatarId=10124" alt="" height="48" width="48" border="0" align="left" style="padding:0;margin: 0 16px 16px 0;" />
                        <div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
                                    <a class="user-hover" rel="rdw@iay.org.uk" id="email_rdw@iay.org.uk" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=rdw%40iay.org.uk" style="color:#326ca6;">Rod Widdowson</a>
     commented on <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/bug.png" height="16" width="16" border="0" align="absmiddle" alt="Bug"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-665'>IDP-665</a>
            </div>
                        <div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
                <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-665'><strong>Warn on sourceAttributeID being specified if is isn&#39;t used</strong></a>
            </div>
                    </td>
    </tr>
</table>
    </td>
</tr>
<tr valign="top">
    <td id="email-fields" style="padding:0 32px 32px 32px;">
        <table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
            <tr valign="top">
                <td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
                <td>
                    <table border="0" cellpadding="0" cellspacing="0" width="100%">
                        <tr valign="top">
    <td colspan="2" style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 16px 0;width:100%;">
        <div class="comment-block" style="background-color:#edf5ff;border:1px solid #dddddd;color:#000000;padding:12px;"><p>After some research it all hangs together, but it should not come as a surprise that at the edges all sorts of infeasible things are possible.</p>

<p>What happens is that after some transmogrification the sourceAttributeID gets turned into a "special sort" of dependency and then (for data connectors only) that specialness is exploited.</p>

<p>But for instance the following</p>

<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-java">&lt;resolver:AttributeDefinition xsi:type=<span class="code-quote">"Simple"</span> xmlns=<span class="code-quote">"urn:mace:shibboleth:2.0:resolver:ad"</span> id=<span class="code-quote">"wibble"</span> &gt;
  &lt;resolver:Dependency ref=<span class="code-quote">"eduPE"</span> /&gt;                &lt;-- An AttributeDefinition --&gt;
  &lt;resolver:Dependency ref=<span class="code-quote">"eduPersonAffiliation"</span> /&gt; &lt;-- An AttributeDefinition --&gt;
&lt;/resolver:AttributeDefinition&gt;
</pre>
</div></div>

<p>Is schema valid, works, and results in "wibble" containing all the attribute values in "eduPE" and "eduPersonAffiliation".</p>

<p>I've not tested but from reading the code </p>
<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-java">&lt;resolver:AttributeDefinition xsi:type=<span class="code-quote">"Simple"</span> xmlns=<span class="code-quote">"urn:mace:shibboleth:2.0:resolver:ad"</span> id=<span class="code-quote">"wibble"</span> sourceAttributeID=<span class="code-quote">"saID"</span>&gt;
  &lt;resolver:Dependency ref=<span class="code-quote">"eduPE"</span> /&gt;                &lt;-- An AttributeDefinition --&gt;
  &lt;resolver:Dependency ref=<span class="code-quote">"eduPersonAffiliation"</span> /&gt; &lt;-- An AttributeDefinition --&gt;
  &lt;resolver:Dependency ref=<span class="code-quote">"DataConnector"</span> /&gt;        &lt;-- A DataConnector --&gt;
&lt;/resolver:AttributeDefinition&gt;
</pre>
</div></div>

<p>Will give all the values from "eduPE", "eduPersonAffiliation" and "saID" (if it exists), plus the contents of the attribute saID from the DataConnector.</p>

<p>This is just plain wrong, but I see no easy way of complaining about based on the way the code works right now.</p>


<p>The bottom line is that the following should <b>require</b> that a sourceAttribute be specified for the following attribute definitions</p>

<p>Prescoped<br/>
Regexp<br/>
Scoped<br/>
Simple<br/>
Mapped<br/>
SAML1NameIdentifierAttributeDefinition<br/>
SAML2NameIDAttributeDefinition</p>

<p>plus the ComputedID DataConnector</p>

<p>In any other case its an error.</p>

<p>I'm inclined to add code to warn the absense of sourceAttributeID in these cases and warn the presence of it in the other cases.  Simplest is to add the warning to the base parser and have a method which the above can return true to toggle the warning behavior.</p>

<p>Thoughts?</p></div>
        <div style="color:#505050;padding:4px 0 0 0;">                </div>
    </td>
</tr>
                    </table>
                </td>
            </tr>
        </table>
    </td>
</tr>













            </table>
        </td><!-- End #email-page -->
    </tr>
    <tr valign="top">
        <td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
            This message is automatically generated by JIRA.<br />
            If you think it was sent incorrectly, please contact your JIRA administrators<br />
            For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
        </td>
    </tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->