<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0">
<base href="https://issues.shibboleth.net/jira">
<title>Message Title</title>
</head>
<body class="jira" style="color: #333333; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.429">
<table id="background-table" cellpadding="0" cellspacing="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; background-color: #f5f5f5; border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt" bgcolor="#f5f5f5">
<!-- header here -->
<tbody>
<tr>
<td id="header-pattern-container" style="padding: 0px; border-collapse: collapse; padding: 10px 20px">
<table id="header-pattern" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt">
<tbody>
<tr>
<td id="header-avatar-image-container" valign="top" style="padding: 0px; border-collapse: collapse; vertical-align: top; width: 32px; padding-right: 8px" width="32"> <img id="header-avatar-image" class="image_fix" src="cid:jira-generated-image-avatar-a3a5da7d-0d36-4fff-b9e3-610a83c1ad45" height="32" width="32" border="0" style="border-radius: 3px; vertical-align: top"> </td>
<td id="header-text-container" valign="middle" style="padding: 0px; border-collapse: collapse; vertical-align: middle; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px"> <a class="user-hover" rel="tzeller@shibboleth.net" id="email_tzeller@shibboleth.net" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=tzeller%40shibboleth.net" style="color:#3b73af;; color: #3b73af; text-decoration: none">Tom Zeller</a> <strong>commented</strong> on <a href="https://issues.shibboleth.net/jira/browse/IDP-1228" style="color: #3b73af; text-decoration: none"><img src="cid:jira-generated-image-avatar-4ff3549a-4380-4687-abb5-d8c22fe9dcd1" height="16" width="16" border="0" align="absmiddle" alt="Bug"> IDP-1228</a> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td id="email-content-container" style="padding: 0px; border-collapse: collapse; padding: 0 20px">
<table id="email-content-table" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; border-spacing: 0; border-collapse: separate">
<tbody>
<tr>
<!-- there needs to be content in the cell for it to render in some clients -->
<td class="email-content-rounded-top mobile-expand" style="padding: 0px; border-collapse: collapse; color: #ffffff; padding: 0 15px 0 16px; height: 15px; background-color: #ffffff; border-left: 1px solid #cccccc; border-top: 1px solid #cccccc; border-right: 1px solid #cccccc; border-bottom: 0; border-top-right-radius: 5px; border-top-left-radius: 5px; height: 10px; line-height: 10px; padding: 0 15px 0 16px; mso-line-height-rule: exactly" height="10" bgcolor="#ffffff"> </td>
</tr>
<tr>
<td class="email-content-main mobile-expand " style="padding: 0px; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff" bgcolor="#ffffff">
<table class="page-title-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt">
<tbody>
<tr>
<td style="vertical-align: top;; padding: 0px; border-collapse: collapse; padding-right: 5px; font-size: 20px; line-height: 30px; mso-line-height-rule: exactly" class="page-title-pattern-header-container"> <span class="page-title-pattern-header" style="font-family: Arial, sans-serif; padding: 0; font-size: 20px; line-height: 30px; mso-text-raise: 2px; mso-line-height-rule: exactly; vertical-align: middle"> <a href="https://issues.shibboleth.net/jira/browse/IDP-1228" style="color: #3b73af; text-decoration: none">Re: Attribute release consent fails (sometimes)</a> </span> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td id="text-paragraph-pattern-top" class="email-content-main mobile-expand comment-top-pattern" style="padding: 0px; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff; border-bottom: none; padding-bottom: 0" bgcolor="#ffffff">
<table class="text-paragraph-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 2px">
<tbody>
<tr>
<td class="text-paragraph-pattern-container mobile-resize-text " style="padding: 0px; border-collapse: collapse; padding: 0 0 10px 0"> <p style="margin: 10px 0 0 0; margin-top: 0">Here is a script to approve any attributes that are not approved.</p> <p style="margin: 10px 0 0 0">I have not tested it rigorously, and I do not fully understand the problem. However, I think deploying and customizing the script is straightforward.</p> <p style="margin: 10px 0 0 0">But first, here is a Java workaround for ExtractConsent to set approve=false only if per-attribute consent is enabled :</p>
<div class="code panel" style="border-width: 1px;; border: 1px solid #cccccc; background: #f5f5f5; font-size: 12px; line-height: 1.333; font-family: monospace; border: 1px solid #cccccc; -moz-border-radius: 3px 3px 3px 3px; border-radius: 3px 3px 3px 3px; margin: 9px 0">
<div class="codeContent panelContent" style="padding: 9px 12px">
<pre class="code-java" style="margin: 10px 0 0 0; margin-top: 0; max-height: 30em; overflow: auto; white-space: pre-wrap; word-wrap: normal">
<span class="code-keyword" style="color: #000091">final</span> Map<<span class="code-object" style="color: #910091">String</span>, Consent> currentConsents = getConsentContext().getCurrentConsents();
<span class="code-keyword" style="color: #000091">for</span> (<span class="code-keyword" style="color: #000091">final</span> Consent consent : currentConsents.values()) {
<span class="code-keyword" style="color: #000091">if</span> (consentIds.contains(consent.getId())) {
consent.setApproved(<span class="code-object" style="color: #910091">Boolean</span>.TRUE);
} <span class="code-keyword" style="color: #000091">else</span> {
<span class="code-comment" style="color: #808080">// Workaround to check whether per-attribute consent is enabled
</span> <span class="code-keyword" style="color: #000091">if</span> (getConsentFlowDescriptor() <span class="code-keyword" style="color: #000091">instanceof</span> AttributeReleaseFlowDescriptor
&& !((AttributeReleaseFlowDescriptor) getConsentFlowDescriptor())
.isPerAttributeConsentEnabled()) {
consent.setApproved(<span class="code-object" style="color: #910091">Boolean</span>.FALSE);
}
}
}
</pre>
</div>
</div> <p style="margin: 10px 0 0 0">However, modifying ExtractConsent involves building a JAR and adding it to the web app.</p> <p style="margin: 10px 0 0 0">So instead, here is a JavaScript Action which will approve any attributes that are not approved.</p> <p style="margin: 10px 0 0 0">Copy the script to idp.home/conf/extract-consent-workaround.js :</p>
<div class="code panel" style="border-width: 1px;; border: 1px solid #cccccc; background: #f5f5f5; font-size: 12px; line-height: 1.333; font-family: monospace; border: 1px solid #cccccc; -moz-border-radius: 3px 3px 3px 3px; border-radius: 3px 3px 3px 3px; margin: 9px 0">
<div class="codeContent panelContent" style="padding: 9px 12px">
<pre class="code-javascript" style="margin: 10px 0 0 0; margin-top: 0; max-height: 30em; overflow: auto; white-space: pre-wrap; word-wrap: normal">
// Create a logger and log message prefix.
<span class="code-keyword" style="color: #000091">var</span> logger = Java.type("org.slf4j.LoggerFactory").getLogger("net.shibboleth.idp.script");
<span class="code-keyword" style="color: #000091">var</span> logPrefix = "ExtractConsentWorkaround :";
// Get the consent context from the profile request context.
<span class="code-keyword" style="color: #000091">var</span> consentContext = profileContext.getSubcontext("net.shibboleth.idp.consent.context.impl.ConsentContext")
logger.debug("{} consent context '{}'", logPrefix, consentContext);
<span class="code-keyword" style="color: #000091">if</span> (consentContext != <span class="code-keyword" style="color: #000091">null</span>) {
// Get the Map<<span class="code-object" style="color: #910091">String</span>,Consent> of consent objects obtained from the user.
<span class="code-keyword" style="color: #000091">var</span> currentConsents = consentContext.getCurrentConsents();
logger.debug("{} current consents '{}'", logPrefix, currentConsents);
// For each consent object representing an attribute ...
<span class="code-keyword" style="color: #000091">for</span> each (<span class="code-keyword" style="color: #000091">var</span> consent <span class="code-keyword" style="color: #000091">in</span> currentConsents.values()) {
<span class="code-keyword" style="color: #000091">if</span> (!consent.isApproved()) {
// ... <span class="code-keyword" style="color: #000091">if</span> consent is not approved, then approve and log.
logger.info("{} approving attribute '{}'", logPrefix, consent.getId());
consent.setApproved(<span class="code-keyword" style="color: #000091">true</span>);
} <span class="code-keyword" style="color: #000091">else</span> {
// ... <span class="code-keyword" style="color: #000091">if</span> consent is approved, great, just log.
logger.debug("{} attribute '{}' is approved", logPrefix, consent.getId());
}
}
}
</pre>
</div>
</div> <p style="margin: 10px 0 0 0">Add workaround script to idp.home/system/flows/intercept/attribute-release-beans.xml :</p>
<div class="code panel" style="border-width: 1px;; border: 1px solid #cccccc; background: #f5f5f5; font-size: 12px; line-height: 1.333; font-family: monospace; border: 1px solid #cccccc; -moz-border-radius: 3px 3px 3px 3px; border-radius: 3px 3px 3px 3px; margin: 9px 0">
<div class="codeContent panelContent" style="padding: 9px 12px">
<pre class="code-xml" style="margin: 10px 0 0 0; margin-top: 0; max-height: 30em; overflow: auto; white-space: pre-wrap; word-wrap: normal">
<bean id=<span class="code-quote" style="color: #009100">"ExtractConsent"</span>
class=<span class="code-quote" style="color: #009100">"net.shibboleth.idp.consent.flow.impl.ExtractConsent"</span> scope=<span class="code-quote" style="color: #009100">"prototype"</span>
p:httpServletRequest-ref=<span class="code-quote" style="color: #009100">"shibboleth.HttpServletRequest"</span> />
<span class="code-tag" style="color: #000091"><span class="code-comment" style="color: #808080"><!-- Workaround to approve all attributes. --></span></span>
<bean id=<span class="code-quote" style="color: #009100">"ExtractConsentWorkaround"</span> class=<span class="code-quote" style="color: #009100">"net.shibboleth.idp.profile.ScriptedAction"</span> scope=<span class="code-quote" style="color: #009100">"prototype"</span>
factory-method=<span class="code-quote" style="color: #009100">"resourceScript"</span> c:resource=<span class="code-quote" style="color: #009100">"../../../conf/extract-consent-workaround.js"</span> />
</pre>
</div>
</div> <p style="margin: 10px 0 0 0">and run the script after ExtractConsent by adding to idp.home/system/flows/intercept/attribute-release-flow.xml :</p>
<div class="code panel" style="border-width: 1px;; border: 1px solid #cccccc; background: #f5f5f5; font-size: 12px; line-height: 1.333; font-family: monospace; border: 1px solid #cccccc; -moz-border-radius: 3px 3px 3px 3px; border-radius: 3px 3px 3px 3px; margin: 9px 0">
<div class="codeContent panelContent" style="padding: 9px 12px">
<pre class="code-xml" style="margin: 10px 0 0 0; margin-top: 0; max-height: 30em; overflow: auto; white-space: pre-wrap; word-wrap: normal">
<span class="code-tag" style="color: #000091"><span class="code-comment" style="color: #808080"><!-- Extract user input from form and update consent objects in consent context accordingly. --></span></span>
<span class="code-tag" style="color: #000091"><action-state id=<span class="code-quote" style="color: #009100">"ExtractConsent"</span>></span>
<span class="code-tag" style="color: #000091"><evaluate expression=<span class="code-quote" style="color: #009100">"ExtractConsent"</span> /></span>
<span class="code-tag" style="color: #000091"><span class="code-comment" style="color: #808080"><!-- Workaround to approve all attributes --></span></span>
<span class="code-tag" style="color: #000091"><evaluate expression=<span class="code-quote" style="color: #009100">"ExtractConsentWorkaround"</span> /></span>
<span class="code-tag" style="color: #000091"><evaluate expression=<span class="code-quote" style="color: #009100">"'AttributeReleaseConsent'"</span> /></span>
<span class="code-tag" style="color: #000091"><transition on=<span class="code-quote" style="color: #009100">"AttributeReleaseConsent"</span> to=<span class="code-quote" style="color: #009100">"AttributeReleaseConsent"</span> /></span>
<span class="code-tag" style="color: #000091"></action-state></span>
</pre>
</div>
</div> <p style="margin: 10px 0 0 0">To turn up debug logging, add to conf/logback.xml :</p>
<div class="code panel" style="border-width: 1px;; border: 1px solid #cccccc; background: #f5f5f5; font-size: 12px; line-height: 1.333; font-family: monospace; border: 1px solid #cccccc; -moz-border-radius: 3px 3px 3px 3px; border-radius: 3px 3px 3px 3px; margin: 9px 0">
<div class="codeContent panelContent" style="padding: 9px 12px">
<pre class="code-xml" style="margin: 10px 0 0 0; margin-top: 0; max-height: 30em; overflow: auto; white-space: pre-wrap; word-wrap: normal">
<span class="code-tag" style="color: #000091"><logger name=<span class="code-quote" style="color: #009100">"net.shibboleth.idp.script"</span> level=<span class="code-quote" style="color: #009100">"DEBUG"</span> /></span>
</pre>
</div>
</div> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td class="email-content-main mobile-expand " style="padding: 0px; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff" bgcolor="#ffffff">
<table id="actions-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px">
<tbody>
<tr>
<td id="actions-pattern-container" valign="middle" style="padding: 0px; border-collapse: collapse; padding: 10px 0 10px 24px; vertical-align: middle; padding-left: 0">
<table align="left" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt">
<tbody>
<tr>
<td class="actions-pattern-action-icon-container" style="padding: 0px; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 0; vertical-align: middle"> <a href="https://issues.shibboleth.net/jira/browse/IDP-1228#add-comment" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none"> <img class="actions-pattern-action-icon-image" src="cid:jira-generated-image-static-comment-icon-ad18a5b1-ecc2-4eb4-b512-d24ea3c94367" alt="Add Comment" title="Add Comment" height="16" width="16" border="0" style="vertical-align: middle"> </a> </td>
<td class="actions-pattern-action-text-container" style="padding: 0px; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 4px; padding-left: 5px"> <a href="https://issues.shibboleth.net/jira/browse/IDP-1228#add-comment" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none">Add Comment</a> </td>
</tr>
</tbody>
</table> </td>
</tr>
</tbody>
</table> </td>
</tr>
<!-- there needs to be content in the cell for it to render in some clients -->
<tr>
<td class="email-content-rounded-bottom mobile-expand" style="padding: 0px; border-collapse: collapse; color: #ffffff; padding: 0 15px 0 16px; height: 5px; line-height: 5px; background-color: #ffffff; border-top: 0; border-left: 1px solid #cccccc; border-bottom: 1px solid #cccccc; border-right: 1px solid #cccccc; border-bottom-right-radius: 5px; border-bottom-left-radius: 5px; mso-line-height-rule: exactly" height="5" bgcolor="#ffffff"> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td id="footer-pattern" style="padding: 0px; border-collapse: collapse; padding: 12px 20px">
<table id="footer-pattern-container" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt">
<tbody>
<tr>
<td id="footer-pattern-text" class="mobile-resize-text" width="100%" style="padding: 0px; border-collapse: collapse; color: #999999; font-size: 12px; line-height: 18px; font-family: Arial, sans-serif; mso-line-height-rule: exactly; mso-text-raise: 2px"> This message was sent by Atlassian JIRA <span id="footer-build-information">(v7.4.2#74004-<span title="586975da6d5c632f4f0de24a42c40182e6b9ead0" data-commit-id="586975da6d5c632f4f0de24a42c40182e6b9ead0}">sha1:586975d</span>)</span> </td>
<td id="footer-pattern-logo-desktop-container" valign="top" style="padding: 0px; border-collapse: collapse; padding-left: 20px; vertical-align: top">
<table style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt">
<tbody>
<tr>
<td id="footer-pattern-logo-desktop-padding" style="padding: 0px; border-collapse: collapse; padding-top: 3px"> <img id="footer-pattern-logo-desktop" src="cid:jira-generated-image-static-footer-desktop-logo-d7fdb0e8-d293-4002-9eaa-c17b438728af" alt="Atlassian logo" title="Atlassian logo" width="169" height="36" class="image_fix"> </td>
</tr>
</tbody>
</table> </td>
</tr>
</tbody>
</table> </td>
</tr>
</tbody>
</table>
</body>
</html>