Default RP config for SAML 1 and attribute-release ?
Tom Zeller
tzeller at dragonacea.biz
Sun Dec 21 17:42:09 EST 2014
> On Dec 21, 2014, at 3:09 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>
>> On 12/21/14, 9:05 PM, "Tom Zeller" <tzeller at dragonacea.biz> wrote:
>>
>> Gosh, I don't think attribute-release is wired into the attribute query
>> flow in v3, or did you do that ? Or maybe I'm confused.
>
> It's not.
>
> If you can't selectively turn off attributes, then the set of attributes
> being consented to is the same set that a query will return if it's done
> in the span of a minute.
>
> If you can only perform a query with a transient ID, then you can only
> query immediately after SSO.
>
> Put the two together and by default, it's not unreasonable to "consent" on
> the front channel to the attributes that will be released on the back
> channel.
>
> Break either of the assumptions and it stops making sense.
>
> -- Scott
Well then, per-attribute should not be enabled for SAML 1. Correct ? Because if ReleaseAttributes is not wired, the user's choices are not honored.
More information about the dev
mailing list