PostAuthenticationFlows for non-SAML profiles
Tom Zeller
tzeller at dragonacea.biz
Fri Aug 21 17:38:02 EDT 2015
>>It seems like the attribute release function is all or nothing. You either
>>accept to release everything or you do not. Is there ever a need to have
>>the user selectively decide which attributes may be release?
>
> I think that model is questionable for most cases, but that was implemented, there's a property that controls it (or at least a config option).
The property to control per-attribute consent is
idp.consent.allowPerAttribute in conf/idp.properties. The doc is
horrible/thin [1].
[1] https://wiki.shibboleth.net/confluence/display/IDP30/ConsentConfiguration#ConsentConfiguration-PerAttributeConsent
More information about the dev
mailing list