Attribute filter

Rod Widdowson rdw at steadingsoftware.com
Tue Jun 24 09:12:58 EDT 2014


I did some end to end testing for the AttributeInMetadata filter this
morning.

I found a couple of important bugs and reminded myself yet again how much I
detest that filter language.  But I did have a couple of questions, none of
which are gating for Alpha ship so if people are busy elsewhere they should
feel free to ignore this mail for a day or two.

I really wanted to test end to end which is to say to start with metadata,
an authenticated user, an attribute-resolver.xml and an attribute-filter.xml
and make sure that everything worked.

For the purposes of my testing I just edited the example attribute-filter
and attribute-resolver which were in idp-conf, ran the test bed and
eyeballed the logs and the result.  This was fine for what I was doing but
I'd like to check in a more durable test.

I did think about adding some explicit flows to idp-config but that didn't
seem to really fit since I wanted to test with the flows that we ship with.
I suspect that it is the best bet, but I'm looking for suggestions for a
good home for such tests (and thus how they should be structured).


My other question is probably for Scott and goes back to our desire to use
the AttributeInMetadata and EntityAttributeInMetadata functors as advanced
replacements for the "AttributeRequestorEntityAttribute*" policy rules.

As deployed in V2 (and despite the class name), the AttributeInMetadata
filter can only be used as a Value filter (it is the only filter with this
restriction), which means that it inherits the attribute it is interested in
from the enclosing <AttributeRule>.

In V3 the filter can be used in attribute rules and in policy rules, but its
utility is pretty much restricted because it isn't tied to any attribute. So
if you say

<PolicyRule xsi:type="saml:AttributeInMetadata" /> it will do the "if any
attribute matches then this is true" behaviour.

I'd like to extend the syntax for this filter to allow an optional
"attributeID", then we look towards say something like

<afp:PolicyRequirementRule xsi:type="saml:EntityAttributeInMetadata"
attributeID="EntityCategory"/>

As an advanced replacement for

<afp:PolicyRequirementRule
xsi:type="saml:AttributeRequesterEntityAttributeExactMatch"
 
attributeName="AttributeRequesterEntityAttributeExactMatch " />

thoughts?

/Rod



More information about the dev mailing list