Stopping users for insufficient attributes at the IdP in v3
Nate Klingenstein
ndk at internet2.edu
Wed Jun 4 23:11:01 EDT 2014
All,
Many commercial SAML products will stop the user at the IdP if they can precalculate that the user would be denied access at the SP due to insufficient attributes or a missing entitlement, but in IdPv2.x, this required writing a custom login handler to accomplish.
I've written treatises on why handling this condition at the SP is better and I'll keep fighting for it, but I'm not winning every battle.
Will it be possible for a deployer of IdPv3 to direct a user to an "insufficient attributes" error page using configuration alone if they choose to do so? Should it be?
Thanks,
Nate.
More information about the dev
mailing list