PostAuthenticationFlows for non-SAML profiles

Tom Zeller tzeller at dragonacea.biz
Fri Aug 21 17:38:02 EDT 2015


>>It seems like the attribute release function is all or nothing. You either
>>accept to release everything or you do not. Is there ever a need to have
>>the user selectively decide which attributes may be release?
>
> I think that model is questionable for most cases, but that was implemented, there's a property that controls it (or at least a config option).

The property to control per-attribute consent is
idp.consent.allowPerAttribute in conf/idp.properties. The doc is
horrible/thin [1].

[1] https://wiki.shibboleth.net/confluence/display/IDP30/ConsentConfiguration#ConsentConfiguration-PerAttributeConsent


More information about the dev mailing list