Delegation: Policy enforcement and ProfileConfiguration resolution
Cantor, Scott
cantor.2 at osu.edu
Mon Sep 28 21:34:42 EDT 2015
Another more radical direction...I guess we could rethink the settings that are not attached in a natural way to the actual RP in the usual sense, which I guess is the end-service the delegate is accessing as the client.
The constraints on the delegate could I guess be reversed to be expressed as "the rule to evaluate to determine whether the request should be allowed" to access a given RP. That could be a Predicate<PRC> that looks at the inbound message context.
The chain length limit is tougher, but...thinking outside the box, could it be embedded in the original assertion (and the subsequent ones) in an extension the IdP consumes, given that it's always signed by the IdP anyway, so is protected?
Just trying to think of alternatives.
-- Scott
More information about the dev
mailing list