What is the "Other party" in Attribute Handling called?
Cantor, Scott
cantor.2 at osu.edu
Thu Feb 21 14:23:26 EST 2013
> As I come to make the changes for this last I realize that it too is subject
> to the "be careful what you call them" rule. So I am polling (mostly Scott
> and Brent) for ideas as to what these should be called so as to be both
> informative and correct.
>
> Principal is easy, but we are somewhat divorced from SAML at this stage so
> "localEntityID" or "SPEntityID" seems wrong at any number of levels.
My suggestion at the meeting was to look at something identifying the specific recipient of the results of the attribute resolution, so perhaps something called AttributeRecipientContext.
I'd like to divorce it from the protocol flow, so that it can be reused. A multiple-recipient use case might execute multiple webflows with the resolver, setting the attribute recipient different each time. Or something more optimized by changing the resolver to understand a multiple recipient context, but either way, the "requester" or "relying party" don't enter into it.
As we discussed earlier, supporting the older scriptlets would involve writing adapter logic to return the right things for the existing requestContext.property lookups.
-- Scott
More information about the dev
mailing list