Formal documentation of the Attribute Filters

Rod Widdowson rdw at steadingsoftware.com
Mon Jul 22 06:23:36 EDT 2013


At the dev meeting on Friday I took an action to start to pull together some
more formal documentation for the Attribute Filter Language (as used in the
SP and in IdP V2 and IdP V3).

I used the SP configuration as a guide and the root of the proposed
documentation starts here:

https://wiki.shibboleth.net/confluence/display/IDP30/IdPXMLSpecifications

It seems to hang together reasonably well, although I had some problems in
working out how to handle the issue that attributes are not necessarily
defined by the Element they occur in.  

Equally, (and to my relief after the issues we had getting the V3 code
written), the documentation for AttributeValueString matcher documentation
was quite challenging, reflecting the basic complexity of the edge cases.

By analogy to the SP (which uses "NativeSP" as a prefix) I used the string
"IdPXML" prefix for all these pages, hence IdPXMLPermitValueRule and so
forth.  This should keep the namespace of whichever space they end up in
relatively clean.  

Comments, either here or in the wiki itself are welcome.

Rod





More information about the dev mailing list