intercept/attribute-release flow with attribute queries in v3
Eric Goodman
Eric.Goodman at ucop.edu
Wed Dec 17 17:54:54 EST 2014
> >AFAICT, the attribute-release intercept flow is currently not meant to
> >used with attribute queries, is that correct?
>
> Another uApprove question...did it maybe know to deactivate itself if the
> profile flow was going to be followed by a query?
>
> That's probably something we should do, bypass the flow if we're in the
> middle of SSO but not including attributes.
FWIW (and probably not much), I raised this scenario with Ken at Tech Exchange to see if LARPP had come up with any guidance/best practices on how to deal with such "out of band" release consent. While he understood the problem, I don't get the sense there was a specific stance/recommendation yet (hence the "probably not much" comment earlier).
Certainly applying the permissions to attribute queries would make it hard to inform the user what was wrong in real time at the SP. Does SAML have a standard way to send a specific, potentially user-facing error message in a failure response? (and is failure even the right response if only some attributes were barred from release by consent)
--- Eric
More information about the dev
mailing list