How to insert detailed message in saml response

Joey Wang carbon_60 at yahoo.com
Thu Jul 7 13:04:39 EDT 2016


Hi, Ayelet, 

No, I do not have experience with ECP flow itself. I can see in your case, your client may need to invoke different workflow based on the IDP error response, so you do need the error info to be included in the SAML response. Based on Scott's response, it looks like IDP code has to be changed to support this. Shibboleth supports extensions in various points of the authentication flow. It probably does not have an officially-sanctioned extension points for this, guessing from Scott's response, but I am wondering, Scott, if there is a way to override the current behavior instead of changing the code of IDP core itself -- I have done something like that myself, overriding the behavior of an internal class, accepting the risk of breaking in the next release of Shibboleth IDP. Since I am not familiar with the ECP flow myself, I cannot give you specifics of how to nor whether it is possible, but that is something you probably can look into.
Joey
 

    On Thursday, July 7, 2016 11:04 AM, ayeletgini <ayelet at hpe.com> wrote:
 

 i see, thank you Scott!



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/How-to-insert-detailed-message-in-saml-response-tp7626525p7626616.html
Sent from the Shibboleth - Developers mailing list archive at Nabble.com.
-- 
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net


   
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20160707/d955536e/attachment.html>


More information about the dev mailing list