AttributeValueMatchesShibMDScopeFunctor.cpp ?

Cantor, Scott cantor.2 at osu.edu
Mon Feb 24 10:36:15 EST 2014


On 2/24/14, 10:26 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:

>It's defined to be single-valued and as such can't be replaced with
>simply extracting shibmd:Scope from SAML metadata in the SP instead
>(as that would potentially result in multiple values; though changing
>the attribute to become multi-valued is not inconcievable itself.)

I'd be more concerned about not having a 1:1 mapping of domain to
"organization with contract", but that's a larger discussion.

>Would it make sense (and would the project consider including a rule
>for schacHomeOrganization to the default attribute-policy.xml) to add
>a copy of the AttributeScopeMatchesShibMDScope functor that matches an
>attribute value (string) against shibmd:Scope, i.e. to create an
>AttributeValueMatchesShibMDScope rule?

Two parts to the question:

- I have no objection to adding any default attributes people want as long
as they're standardized in an appropriate way and not just ad hoc.

- Having a filter functor like that would be fine, modulo that I can't
really say when a 2.6 might emerge.

-- Scott




More information about the dev mailing list