<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"> 
    <head> 
        <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> 
        <meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0"> 
        <base href="https://shibboleth.atlassian.net"> 
        <title>Message Title</title> 
    </head> 
    <body class="jira" style="color: #333333; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.429"> 
        <table id="background-table" cellpadding="0" cellspacing="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0; background-color: #f5f5f5; border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0" bgcolor="#f5f5f5"> <!-- header here --> 
            <tbody>
                <tr> 
                    <td id="header-pattern-container" style="padding: 0; border-collapse: collapse; padding: 10px 20px"> 
                        <table id="header-pattern" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0"> 
                            <tbody>
                              <tr> 
                              <td id="header-avatar-image-container" valign="top" style="padding: 0; border-collapse: collapse; vertical-align: top; width: 32px; padding-right: 8px" width="32"> <img id="header-avatar-image" class="image_fix" src="https://secure.gravatar.com/avatar/0316dae1128c1bac2a50be6df06a2233?d=https%3A%2F%2Favatar-management--avatars.us-west-2.prod.public.atl-paas.net%2Finitials%2FHM-0.png" height="32" width="32" border="0" style="border-radius: 3px; vertical-align: top"> </td> 
                              <td id="header-text-container" valign="middle" style="padding: 0; border-collapse: collapse; vertical-align: middle; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px"> <a class="user-hover" rel="557058:1614c4a5-c89e-4edc-9421-990bd6ea85fd" style="color:#3b73af;; color: #3b73af; text-decoration: none" id="email_557058:1614c4a5-c89e-4edc-9421-990bd6ea85fd" href="https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A1614c4a5-c89e-4edc-9421-990bd6ea85fd"> Henri Mikkonen </a> <strong>commented</strong> on <a href="https://shibboleth.atlassian.net/browse/JOIDC-6?atlOrigin=eyJpIjoiMGQzOGZlZjJjMTE2NDU4NThmMDJhZmU0ZDk0MjU5ZDkiLCJwIjoiaiJ9" style="color: #3b73af; text-decoration: none"><img src="cid:jira-generated-image-avatar-fb06b281-de0d-4c60-b124-ea01e2d50ca8" height="16" width="16" border="0" align="absmiddle" alt="Improvement"> JOIDC-6</a> </td> 
                              </tr> 
                            </tbody>
                        </table> </td> 
                </tr> 
                <tr> 
                    <td id="email-content-container" style="padding: 0; border-collapse: collapse; padding: 0 20px"> 
                        <table id="email-content-table" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0; border-spacing: 0; border-collapse: separate"> 
                            <tbody>
                              <tr> <!-- there needs to be content in the cell for it to render in some clients --> 
                              <td class="email-content-rounded-top mobile-expand" style="padding: 0; border-collapse: collapse; color: #ffffff; padding: 0 15px 0 16px; height: 15px; background-color: #ffffff; border-left: 1px solid #cccccc; border-top: 1px solid #cccccc; border-right: 1px solid #cccccc; border-bottom: 0; border-top-right-radius: 5px; border-top-left-radius: 5px; height: 10px; line-height: 10px; padding: 0 15px 0 16px; mso-line-height-rule: exactly" height="10" bgcolor="#ffffff"> </td> 
                              </tr> 
                              <tr> 
                              <td class="email-content-main mobile-expand " style="padding: 0; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff" bgcolor="#ffffff"> 
                              <table class="page-title-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0"> 
                              <tbody>
                              <tr> 
                              <td style="vertical-align: top;; padding: 0; border-collapse: collapse; padding-right: 5px; font-size: 20px; line-height: 30px; mso-line-height-rule: exactly" class="page-title-pattern-header-container"> <span class="page-title-pattern-header" style="font-family: Arial, sans-serif; padding: 0; font-size: 20px; line-height: 30px; mso-text-raise: 2px; mso-line-height-rule: exactly; vertical-align: middle"> <a href="https://shibboleth.atlassian.net/browse/JOIDC-6?atlOrigin=eyJpIjoiMGQzOGZlZjJjMTE2NDU4NThmMDJhZmU0ZDk0MjU5ZDkiLCJwIjoiaiJ9" style="color: #3b73af; text-decoration: none">Re: Release policy for OAuth2 scope values based on IdPAttributes</a> </span> </td> 
                              </tr> 
                              </tbody>
                              </table> </td> 
                              </tr> 
                              <tr> 
                              <td id="text-paragraph-pattern-top" class="email-content-main mobile-expand  comment-top-pattern" style="padding: 0; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff; border-bottom: none; padding-bottom: 0" bgcolor="#ffffff"> 
                              <table class="text-paragraph-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 2px"> 
                              <tbody>
                              <tr> 
                              <td class="text-paragraph-pattern-container mobile-resize-text " style="padding: 0; border-collapse: collapse; padding: 0 0 10px"> <p style="margin: 10px 0 0; margin-top: 0">The following example describes how the allowed scope set can be modified according to the authenticated users' attributes.</p> <p style="margin: 10px 0 0">In conf/global.xml, specify the function <b>shibboleth.oidc.AllowedScopeStrategy</b> (in this case together with a HelperPair to be able to exploit the default function and attribute resolver service):</p> 
                              <div class="preformatted panel" style="border-width: 1px;; border: 1px solid #cccccc; background: #f5f5f5; font-size: 12px; line-height: 1.333; font-family: monospace; border: 1px solid #cccccc; -moz-border-radius: 3px; border-radius: 3px; margin: 9px 0">
                              <div class="preformattedContent panelContent" style="padding: 9px 12px"> 
                              <pre style="margin: 10px 0 0; margin-top: 0; max-height: 30em; overflow: auto; white-space: pre-wrap; word-wrap: normal; white-space: pre; word-break: normal; word-wrap: break-word; word-break: break-all; white-space: pre-wrap">    <bean id="shibboleth.oidc.AllowedScopeStrategy.HelperPair"
          class="net.shibboleth.utilities.java.support.collection.Pair"
          p:first-ref="shibboleth.AttributeResolverService"
          p:second-ref="shibboleth.oidc.DefaultAllowedScopeStrategy" />

    <bean id="shibboleth.oidc.AllowedScopeStrategy"
          parent="shibboleth.Functions.Scripted"
          p:customObject-ref="shibboleth.oidc.AllowedScopeStrategy.HelperPair"
          factory-method="inlineScript">
        <constructor-arg name="scriptSource">
            <value>
                <![CDATA[
                var logger = Java.type("org.slf4j.LoggerFactory").getLogger("net.shibboleth.idp.plugin.oidc.op.profile.AllowedScopeStrategy");
                authCtx = input.getSubcontext("net.shibboleth.idp.authn.context.AuthenticationContext");
                usernameLookupStrategyClass = Java.type("net.shibboleth.idp.session.context.navigate.CanonicalUsernameLookupStrategy");
                usernameLookupStrategy = new usernameLookupStrategyClass();
                username = usernameLookupStrategy.apply(input);
                result = custom.getSecond().apply(input);
                if (username != null) {
                    resCtx = input.getSubcontext("net.shibboleth.idp.attribute.resolver.context.AttributeResolutionContext", true);
                    resCtx.setPrincipal(username);
                    resCtx.resolveAttributes(custom.getFirst());
                    attribute = resCtx.getResolvedIdPAttributes().get("allowedScope");
                    if (attribute != null && attribute.getValues().size() > 0) {
                        logger.debug("Setting new scope value from allowedScope attribute");
                        result = Java.type("net.shibboleth.idp.plugin.oidc.op.profile.ScopeUtil").buildScope(attribute);
                    } else {
                        logger.debug("Keeping the existing scope value");
                    }
                    input.removeSubcontext(resCtx); // cleanup
                }
                logger.debug("Scope to be returned: " + result);
                result;
                ]]>
            </value>
        </constructor-arg>
    </bean>
</pre> 
                              </div>
                              </div> <p style="margin: 10px 0 0">The function checks if username can be resolved and if yes, resolves user’s attribute via resolver service. If an attribute <tt>allowedScope</tt> is resolved, its value will be used as the allowed scope for this user. If the username cannot be resolved (for instance with the backend flows) or the attribute <tt>allowedScope</tt> is not resolved, the value returned by the default function (<tt>shibboleth.oidc.DefaultAllowedScopeStrategy</tt>) is returned. It corresponds to the scope specified in the RP metadata.</p> <p style="margin: 10px 0 0">The attribute-resolver snippet below shows one example for specifying the <tt>allowedScope</tt> attribute:</p> 
                              <div class="preformatted panel" style="border-width: 1px;; border: 1px solid #cccccc; background: #f5f5f5; font-size: 12px; line-height: 1.333; font-family: monospace; border: 1px solid #cccccc; -moz-border-radius: 3px; border-radius: 3px; margin: 9px 0">
                              <div class="preformattedContent panelContent" style="padding: 9px 12px"> 
                              <pre style="margin: 10px 0 0; margin-top: 0; max-height: 30em; overflow: auto; white-space: pre-wrap; word-wrap: normal; white-space: pre; word-break: normal; word-wrap: break-word; word-break: break-all; white-space: pre-wrap">    <AttributeDefinition id="allowedScope" xsi:type="ScriptedAttribute">
        <InputDataConnector ref="oAuth2ScopeConnector" attributeNames="defaultAllowedScope"/>
        <InputDataConnector ref="staticAttributes" attributeNames="phone_number_verified"/>
        <Script><![CDATA[
            logger = Java.type("org.slf4j.LoggerFactory").getLogger("net.shibboleth.attribute.allowedSope");
            ScopeUtil = Java.type("net.shibboleth.idp.plugin.oidc.op.profile.ScopeUtil");
            var phoneVerified = "";
            if (typeof phone_number_verified != "undefined" && phone_number_verified.getValues().size() > 0) {
               phoneVerified = phone_number_verified.getValues().get(0);
            }
            if (phoneVerified.equals("true")) {
               logger.debug("Keeping scope as it was");
               ScopeUtil.populateScriptedAttribute(allowedScope, defaultAllowedScope);
            } else {
               logger.debug("Removing 'phone' from the scopes");
               newScope = ScopeUtil.buildScope(defaultAllowedScope);
               ScopeUtil.removeValue(newScope, "phone");
               newAttribute = ScopeUtil.populateScriptedAttribute(allowedScope, newScope);
            }
        ]]></Script>
    </AttributeDefinition>

    <DataConnector id="oAuth2ScopeConnector" xsi:type="ScriptedDataConnector" customObjectRef="shibboleth.oidc.DefaultAllowedScopeStrategy">
        <Script><![CDATA[
            defaultAllowedScope = custom.apply(profileContext);
            scopeAsAttribute = Java.type("net.shibboleth.idp.plugin.oidc.op.profile.ScopeUtil").buildAttribute("defaultAllowedScope", defaultAllowedScope);
            connectorResults.add(scopeAsAttribute);
        ]]></Script>
    </DataConnector></pre> 
                              </div>
                              </div> <p style="margin: 10px 0 0">In this example, the <tt>allowedScope</tt> is defined so that <b>phone</b> value is removed from the default scope, if the attribute <tt>phone_number_verified</tt> is not set to <b>true</b>.</p> <p style="margin: 10px 0 0">Obviously this specific example could have been implemented solely inside single <b>shibboleth.oidc.AllowedScopeStrategy</b> function, but the attribute-resolver snippet was included to demonstrate how its features may be exploited too in this context.</p> </td> 
                              </tr> 
                              </tbody>
                              </table> </td> 
                              </tr> 
                              <tr> 
                              <td class="email-content-main mobile-expand " style="padding: 0; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff" bgcolor="#ffffff"> <script type="application/ld+json">
{
  "@context": "http://schema.org",
  "@type": "EmailMessage",
  "description": "View Issue",
  "potentialAction": {
    "@type": "ViewAction",
        "target": "https://shibboleth.atlassian.net/browse/JOIDC-6?inbox=true&focusedCommentId=32926&page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel#comment-32926",
    "name": "View Comment"
      },
  "publisher": {
    "@type": "Organization",
    "name": "Atlassian",
    "url": "https://www.atlassian.com"
  }
}
</script> 
                              <table id="actions-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px"> 
                              <tbody>
                              <tr> 
                              <td id="actions-pattern-container" valign="middle" style="padding: 0; border-collapse: collapse; padding: 10px 0 10px 24px; vertical-align: middle; padding-left: 0"> 
                              <table align="left" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0"> 
                              <tbody>
                              <tr> 
                              <td class="actions-pattern-action-icon-container" style="padding: 0; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 0; vertical-align: middle"> <a href="https://shibboleth.atlassian.net/browse/JOIDC-6#add-comment?atlOrigin=eyJpIjoiMGQzOGZlZjJjMTE2NDU4NThmMDJhZmU0ZDk0MjU5ZDkiLCJwIjoiaiJ9" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none"> <img class="actions-pattern-action-icon-image" src="cid:jira-generated-image-static-comment-icon-bab07e25-e064-4fe8-ba26-69315c5cd304" alt="Add Comment" title="Add Comment" height="16" width="16" border="0" style="vertical-align: middle"> </a> </td> 
                              <td class="actions-pattern-action-text-container" style="padding: 0; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 4px; padding-left: 5px"> <a href="https://shibboleth.atlassian.net/browse/JOIDC-6#add-comment?atlOrigin=eyJpIjoiMGQzOGZlZjJjMTE2NDU4NThmMDJhZmU0ZDk0MjU5ZDkiLCJwIjoiaiJ9" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none">Add Comment</a> </td> 
                              </tr> 
                              </tbody>
                              </table> </td> 
                              </tr> 
                              </tbody>
                              </table> </td> 
                              </tr> <!-- there needs to be content in the cell for it to render in some clients --> 
                              <tr> 
                              <td class="email-content-rounded-bottom mobile-expand" style="padding: 0; border-collapse: collapse; color: #ffffff; padding: 0 15px 0 16px; height: 5px; line-height: 5px; background-color: #ffffff; border-top: 0; border-left: 1px solid #cccccc; border-bottom: 1px solid #cccccc; border-right: 1px solid #cccccc; border-bottom-right-radius: 5px; border-bottom-left-radius: 5px; mso-line-height-rule: exactly" height="5" bgcolor="#ffffff"> </td> 
                              </tr> 
                            </tbody>
                        </table> </td> 
                </tr> 
                <tr> 
                    <td id="footer-pattern" style="padding: 0; border-collapse: collapse; padding: 12px 20px"> 
                        <table id="footer-pattern-container" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0"> 
                            <tbody>
                              <tr> 
                              <td id="footer-pattern-mobile-separated-links" class="mobile-resize-text" width="100%" colspan="2" style="padding: 0; border-collapse: collapse; color: #999999; font-size: 12px; line-height: 18px; font-family: Arial, sans-serif; mso-line-height-rule: exactly; mso-text-raise: 2px"> Get Jira notifications on your phone! Download the Jira Cloud app for <a href="https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail" style="color: #3b73af; text-decoration: none">Android</a> or <a href="https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8" style="color: #3b73af; text-decoration: none">iOS</a> 
                              <hr> </td> 
                              </tr> 
                              <tr> 
                              <td id="footer-pattern-text" class="mobile-resize-text" width="100%" style="padding: 0; border-collapse: collapse; color: #999999; font-size: 12px; line-height: 18px; font-family: Arial, sans-serif; mso-line-height-rule: exactly; mso-text-raise: 2px"> This message was sent by Atlassian Jira <span id="footer-build-information">(v1001.0.0-SNAPSHOT#100201-<span title="07cea574a19aa3619c59f4bfb76602a8e96a0dea" data-commit-id="07cea574a19aa3619c59f4bfb76602a8e96a0dea}">sha1:07cea57</span>)</span> </td> 
                              <td id="footer-pattern-logo-desktop-container" valign="top" style="padding: 0; border-collapse: collapse; padding-left: 20px; vertical-align: top"> 
                              <table style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0"> 
                              <tbody>
                              <tr> 
                              <td id="footer-pattern-logo-desktop-padding" style="padding: 0; border-collapse: collapse; padding-top: 3px; opacity: 0.150"> <img id="footer-pattern-logo-desktop" src="cid:jira-generated-image-static-footer-desktop-logo-e9af1f58-98e3-48bf-bada-f96ad035538f" alt="Atlassian logo" title="Atlassian logo" width="192" height="24" class="image_fix"> </td> 
                              </tr> 
                              </tbody>
                              </table> </td> 
                              </tr> 
                            </tbody>
                        </table> </td> 
                </tr> 
            </tbody>
        </table>  
    </body>
</html>