Assurance Enhancements for IdPv2

Cantor, Scott cantor.2 at osu.edu
Tue May 21 10:53:43 EDT 2013


> Thanks for the link.  At first glance it looks like one might be able
> to write a V3 authentication flow that delegates to Spring Security or
> Shiro or whatever for primary authentication as long as authN flow
> translates the results back to the V3 contract appropriately.

A web flow can basically do anything it wants, so I don't know of anything that shouldn't work if it's hidden inside one.

> Yes, it would be good to stay in alignment if possible.  One of the
> discussion points at IIW was building something of a V3 facade that
> would hide V2 complexity from the MCB and make it more future-proof.

That's what I had in mind. It just depends how complex the façade has to be.

-- Scott





More information about the dev mailing list