uApprove JP 2.5.0 released (Re: v3 consent to attribute release : required vs optional attrs ?)
Michael A Grady
mgrady at unicon.net
Wed Sep 3 16:42:07 EDT 2014
On Sep 3, 2014, at 11:17 AM, Nate Klingenstein <ndk at internet2.edu> wrote:
>>> Thanks for the heads up. I would strongly encourage the people behind
>>> PrivacyLens to talk to you guys since they're essentially duplicating your
>>> work.
>>
>> Maybe we should devote part of a dev call to v3 consent, for
>> interested parties to get together.
>
> I'll extend the offer to the PL team.
>
I haven't been involved at all in the direct development of PrivacyLens (PL), but my understanding is the PL team started with uApprove, and the GakuNin variation on it, as a base to learn from and build on. There is reuse of code from uApprove (not sure about from uApprove.jp or not). Duplicating work was not the intent; the intent was to explore a new user interface, a different way to present the consent dialogue and have more supporting information ("metadata") around why those attributes were being requested, what might be done with them, and why one might want to release optional attributes. With the decisions on what kind of information should be available, and how it might be presented to the user, based on doing research with focus groups.
Now since there was even more configuration needed per service in order to provide all the supporting information that the team working on PrivacyLens felt needs to be available, some of the approaches that uApprove started, and GakuNin pushed further, in terms of adding elements to current IdP config files (attribute-resolver) and SAML metadata (RequestedAttributeExtension) were not pursued (at least to date). Instead, it adds a JSON config file to carry a lot of this info now. So that's perhaps the other notable variation from GakuNin/uApprove at this time.
The install documentation for PL draws heavily from uApprove, as much of what you need to do is exactly the same. Since a lot of the underlying approaches and some of the code was based on uApprove.
--
Michael A. Grady
Senior IAM Consultant, Unicon, Inc.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20140903/13a7ed3b/attachment.html
More information about the dev
mailing list