Is Oauth in the Shibboleth roadmap?
Cantor, Scott
cantor.2 at osu.edu
Mon Jun 12 14:35:51 EDT 2017
On 6/12/17, 4:14 AM, "dev on behalf of Jean-Baptiste BOHUON" <dev-bounces at shibboleth.net on behalf of jean-baptiste.bohuon at inra.fr> wrote:
> May I ask if it is in the development roadmap of Shibboleth?
Our roadmap is always publically available and periodically updated. [1] It accurately eflects the state of matters, which is that OIDC support is a resource issue but understood to be a requirement, so it's under Planned, while OAuth in a more general sense would have to be much more defined as a use case to do anything significant, so it's in a looser category.
GEANT has a project to develop OIDC support on top of the V3 code base and the organization the developers work for has committed to at least some period of maintenance and support after the project ends. It is not likely we would do anything until that work is done and being evaluated, no matter what resources we had.
The project team has already spent time in some minor consulting on the design and doing library reviews and will do more as time permits. Beyond that, there are insufficient resources to commit to taking on such a substantial new amount of technical debt, and nobody committing to volunteer to do it for an extended period of time by joining the project, so there is no commitment to ship anything unless something changes, more people join the project, or we drop something.
RENATER, as a consortium member, has a voice in what we do or don't do, and in shaping the financial strategy necessary to do what the members believe is necessary. If you're asking on behalf of a RENATER member organization, that's an avenue to pursue. The members ultimately control what we do.
-- Scott
[1] https://wiki.shibboleth.net/confluence/display/DEV/Project+Roadmap
More information about the dev
mailing list