<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
    <head> 
        <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> 
        <meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0"> 
        <base href="https://issues.shibboleth.net/jira"> 
        <title>Message Title</title> 
    </head> 
    <body class="jira" style="color: #333333; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.429"> 
        <table id="background-table" cellpadding="0" cellspacing="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; background-color: #f5f5f5; border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt" bgcolor="#f5f5f5"> 
            <!-- header here --> 
            <tbody>
                <tr> 
                    <td id="header-pattern-container" style="padding: 0px; border-collapse: collapse; padding: 10px 20px"> 
                        <table id="header-pattern" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt"> 
                            <tbody>
                                <tr> 
                                    <td id="header-avatar-image-container" valign="top" style="padding: 0px; border-collapse: collapse; vertical-align: top; width: 32px; padding-right: 8px" width="32"> <img id="header-avatar-image" class="image_fix" src="cid:jira-generated-image-avatar-e7dde28b-3d80-494a-a0fa-4aa08e8d0ec3" height="32" width="32" border="0" style="border-radius: 3px; vertical-align: top"> </td> 
                                    <td id="header-text-container" valign="middle" style="padding: 0px; border-collapse: collapse; vertical-align: middle; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px"> <a class="user-hover" rel="rdw@iay.org.uk" id="email_rdw@iay.org.uk" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=rdw%40iay.org.uk" style="color:#0052cc;; color: #3b73af; text-decoration: none">Rod Widdowson</a> <strong>commented</strong> on <a href="https://issues.shibboleth.net/jira/browse/IDP-1235" style="color: #3b73af; text-decoration: none"><img src="cid:jira-generated-image-avatar-c4b11e8a-0811-491a-ae9a-a0773388138d" height="16" width="16" border="0" align="absmiddle" alt="Improvement"> IDP-1235</a> </td> 
                                </tr> 
                            </tbody>
                        </table> </td> 
                </tr> 
                <tr> 
                    <td id="email-content-container" style="padding: 0px; border-collapse: collapse; padding: 0 20px"> 
                        <table id="email-content-table" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; border-spacing: 0; border-collapse: separate"> 
                            <tbody>
                                <tr> 
                                    <!-- there needs to be content in the cell for it to render in some clients --> 
                                    <td class="email-content-rounded-top mobile-expand" style="padding: 0px; border-collapse: collapse; color: #ffffff; padding: 0 15px 0 16px; height: 15px; background-color: #ffffff; border-left: 1px solid #cccccc; border-top: 1px solid #cccccc; border-right: 1px solid #cccccc; border-bottom: 0; border-top-right-radius: 5px; border-top-left-radius: 5px; height: 10px; line-height: 10px; padding: 0 15px 0 16px; mso-line-height-rule: exactly" height="10" bgcolor="#ffffff"> </td> 
                                </tr> 
                                <tr> 
                                    <td class="email-content-main mobile-expand " style="padding: 0px; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff" bgcolor="#ffffff"> 
                                        <table class="page-title-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt"> 
                                            <tbody>
                                                <tr> 
                                                    <td style="vertical-align: top;; padding: 0px; border-collapse: collapse; padding-right: 5px; font-size: 20px; line-height: 30px; mso-line-height-rule: exactly" class="page-title-pattern-header-container"> <span class="page-title-pattern-header" style="font-family: Arial, sans-serif; padding: 0; font-size: 20px; line-height: 30px; mso-text-raise: 2px; mso-line-height-rule: exactly; vertical-align: middle"> <a href="https://issues.shibboleth.net/jira/browse/IDP-1235" style="color: #3b73af; text-decoration: none">Re: Dependencies of disabled plugins should be exposed</a> </span> </td> 
                                                </tr> 
                                            </tbody>
                                        </table> </td> 
                                </tr> 
                                <tr> 
                                    <td id="text-paragraph-pattern-top" class="email-content-main mobile-expand  comment-top-pattern" style="padding: 0px; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff; border-bottom: none; padding-bottom: 0" bgcolor="#ffffff"> 
                                        <table class="text-paragraph-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 2px"> 
                                            <tbody>
                                                <tr> 
                                                    <td class="text-paragraph-pattern-container mobile-resize-text " style="padding: 0px; border-collapse: collapse; padding: 0 0 10px 0"> <p style="margin: 10px 0 0 0; margin-top: 0">Well "Jings crivens help ma boab", this might not be too hard. But there are subtleties which <em>might</em> make this too weird.</p> <p style="margin: 10px 0 0 0">Firstly, what does the current resolver do?</p> 
                                                        <ul> 
                                                            <li>It resolves every "exporting" data connector, populating the results into the work context 
                                                                <ul> 
                                                                    <li>Note that resolving a data connector will resolve dependencies recursively (see below)</li> 
                                                                </ul> </li> 
                                                            <li>It gets the list of attributes that are to be resolved (the requested ones or all of them)</li> 
                                                            <li>It then iterates over this list, resolving each one. 
                                                                <ul> 
                                                                    <li>Note that resolving an AttributeDefinition (or DataConnector) will resolve dependencies recursively (see below)</li> 
                                                                </ul> </li> 
                                                            <li>When all is done all resolved attributes are decanted into the Attribute Context from the work context. 
                                                                <ul> 
                                                                    <li>Dependency Only attributes are NOT exported.</li> 
                                                                </ul> </li> 
                                                            <li>Then the exporting data connectors are decanted into the Attribute Context 
                                                                <ul> 
                                                                    <li>But clashing attribute names do not overwrite previously set resolved attributes (it warns)</li> 
                                                                </ul> </li> 
                                                        </ul> <p style="margin: 10px 0 0 0">Resolving an AttributeDefiniton/DataConnector involves:</p> 
                                                        <ul> 
                                                            <li>Getting a list of all the dependent AttributeDefinition and DataConnector</li> 
                                                            <li>Recursively Resolving each dependent AttributeDefinition or DataConnector</li> 
                                                            <li>Resolve the AttributeDefiniton/DataConnector 
                                                                <ul> 
                                                                    <li>Call the ActivationCondition and skip if needs be</li> 
                                                                    <li>Call the doResolve method.</li> 
                                                                </ul> </li> 
                                                        </ul> <p style="margin: 10px 0 0 0">I <em>think</em> that 'all' one has to do is to</p> 
                                                        <ul> 
                                                            <li>Do the two decant operations during each Attribute or DataConnector resolution between the recursive call to resolve dependencies and the actual resolution (i.e. prior to the activation condition be tested).</li> 
                                                            <li>The decanting would need to be changed slightly: 
                                                                <ul> 
                                                                    <li>The warning on DataConnectors not overwriting previously resolved AttrtibuteDefinitions would need to be supressed since there is no way of distinguishing a data connector sourced attribute which is just being re-decanted becasue we are calling decant repeatedly</li> 
                                                                    <li>We would have to decant dependencyOnly attributes, otherwise they would not be available to the activation conditions.</li> 
                                                                </ul> </li> 
                                                            <li>Prior to the current "decant stage" would would explicitly empty the "resolvedAttributes" list so that when the decanting was done properly and for real we could do the right thing by way of warning and handling dependencyOnly definitions.</li> 
                                                        </ul> <p style="margin: 10px 0 0 0">The subtleties are:</p> 
                                                        <ul> 
                                                            <li>There is a little bit more heap churn since the resolved attributes will mostly be generated twice (at least). I don't think I care.</li> 
                                                            <li>The "decant in flght" semantics might mean that activation conditions see attributes which don't look anything like the end result. Two examples: 
                                                                <ul> 
                                                                    <li>A DataConnector exports attribute "foo" as does an AttributeDefinition. If the data connector is resolved first then the context will contain the bogus definition of foo, right up to the moment that the AttributeDefinition is first resolved.</li> 
                                                                    <li>A DataConnector exports an attribute "foo" as does an AttributeDefinition, only the AttributeDefinition is marked dependencyOnly. In this case the AttributeDefinition will always be present in the context during resolution but it will be the data connector derived attribute that is present after resolution.</li> 
                                                                    <li>There may be homologs in the ScriptedAttributeDefinition</li> 
                                                                </ul> </li> 
                                                            <li>In many cases the AttributeWork Context will contain many more attributes ("everything so far") than are available via the usual mechanism ("The explicit dependencies").</li> 
                                                        </ul> <p style="margin: 10px 0 0 0">The first two bullets could be relaxed (and possibly even removed) by justnot decanting exporting data connectors, but that would just cause confusion (I believe). My preferred solution would be to add copious TRACE level logging of this new stuff.</p> <p style="margin: 10px 0 0 0">I don't think that I care much about the last bullet.</p> <p style="margin: 10px 0 0 0"> </p> <p style="margin: 10px 0 0 0">Comments welcome, otherwise I'll let this site for a while and then action it.</p> </td> 
                                                </tr> 
                                            </tbody>
                                        </table> </td> 
                                </tr> 
                                <tr> 
                                    <td class="email-content-main mobile-expand " style="padding: 0px; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff" bgcolor="#ffffff"> 
                                        <table id="actions-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px"> 
                                            <tbody>
                                                <tr> 
                                                    <td id="actions-pattern-container" valign="middle" style="padding: 0px; border-collapse: collapse; padding: 10px 0 10px 24px; vertical-align: middle; padding-left: 0"> 
                                                        <table align="left" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt"> 
                                                            <tbody>
                                                                <tr> 
                                                                    <td class="actions-pattern-action-icon-container" style="padding: 0px; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 0; vertical-align: middle"> <a href="https://issues.shibboleth.net/jira/browse/IDP-1235#add-comment" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none"> <img class="actions-pattern-action-icon-image" src="cid:jira-generated-image-static-comment-icon-0e909db4-45ed-46e0-97de-33f7e8e15ef9" alt="Add Comment" title="Add Comment" height="16" width="16" border="0" style="vertical-align: middle"> </a> </td> 
                                                                    <td class="actions-pattern-action-text-container" style="padding: 0px; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 4px; padding-left: 5px"> <a href="https://issues.shibboleth.net/jira/browse/IDP-1235#add-comment" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none">Add Comment</a> </td> 
                                                                </tr> 
                                                            </tbody>
                                                        </table> </td> 
                                                </tr> 
                                            </tbody>
                                        </table> </td> 
                                </tr> 
                                <!-- there needs to be content in the cell for it to render in some clients --> 
                                <tr> 
                                    <td class="email-content-rounded-bottom mobile-expand" style="padding: 0px; border-collapse: collapse; color: #ffffff; padding: 0 15px 0 16px; height: 5px; line-height: 5px; background-color: #ffffff; border-top: 0; border-left: 1px solid #cccccc; border-bottom: 1px solid #cccccc; border-right: 1px solid #cccccc; border-bottom-right-radius: 5px; border-bottom-left-radius: 5px; mso-line-height-rule: exactly" height="5" bgcolor="#ffffff"> </td> 
                                </tr> 
                            </tbody>
                        </table> </td> 
                </tr> 
                <tr> 
                    <td id="footer-pattern" style="padding: 0px; border-collapse: collapse; padding: 12px 20px"> 
                        <table id="footer-pattern-container" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt"> 
                            <tbody>
                                <tr> 
                                    <td id="footer-pattern-text" class="mobile-resize-text" width="100%" style="padding: 0px; border-collapse: collapse; color: #999999; font-size: 12px; line-height: 18px; font-family: Arial, sans-serif; mso-line-height-rule: exactly; mso-text-raise: 2px"> This message was sent by Atlassian Jira <span id="footer-build-information">(v8.2.3#802003-<span title="5986657bbb45d2d15e7e179e83f09254924a6523" data-commit-id="5986657bbb45d2d15e7e179e83f09254924a6523}">sha1:5986657</span>)</span> </td> 
                                    <td id="footer-pattern-logo-desktop-container" valign="top" style="padding: 0px; border-collapse: collapse; padding-left: 20px; vertical-align: top"> 
                                        <table style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt"> 
                                            <tbody>
                                                <tr> 
                                                    <td id="footer-pattern-logo-desktop-padding" style="padding: 0px; border-collapse: collapse; padding-top: 3px"> <img id="footer-pattern-logo-desktop" src="https://issues.shibboleth.net/jira/images/mail/atlassian-email-logo.png" alt="Atlassian logo" title="Atlassian logo" width="191" height="24" class="image_fix"> </td> 
                                                </tr> 
                                            </tbody>
                                        </table> </td> 
                                </tr> 
                            </tbody>
                        </table> </td> 
                </tr> 
            </tbody>
        </table>   
    </body>
</html>