Defining a scoping element in an authentication request
Hoorn, R. van der (Robbert)
R.vanderHoorn at dictu.nl
Tue Aug 23 12:51:07 UTC 2022
Hi dev,
We have a SAML broker that connects us to 3 IDP's (Dutch Government: eHerkenning, Digid and eIDAS). The broker lets the user choose which IDP to connect to.
Now the client application has a "smart login screen" which lets the user choose up-front, and they insist on keeping that. The only way to tell the broker about this choice is to add a scoping element to the authn request, indicating the IDP to use. (not my idea, theirs!). Is there a way to add a scoping element to the request, once intercepted by the SP? I can't find anything in the docs but I'm relatively new to Shibboleth...
Regards,
Robbert
Dit bericht kan informatie bevatten die niet voor u is bestemd. Indien u
niet de geadresseerde bent of dit bericht abusievelijk aan u is gezonden,
wordt u verzocht dat aan de afzender te melden en het bericht te
verwijderen.
De Staat aanvaardt geen aansprakelijkheid voor schade, van welke aard
ook, die verband houdt met risico's verbonden aan het elektronisch
verzenden van berichten.
This message may contain information that is not intended for you. If you
are not the addressee or if this message was sent to you by mistake, you
are requested to inform the sender and delete the message.
The State accepts no liability for damage of any kind resulting from the
risks inherent in the electronic transmission of messages.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20220823/b26588a3/attachment.htm>
More information about the dev
mailing list