WebAuthn: Issue with Fido metadata?

Cantor, Scott cantor.2 at osu.edu
Tue Oct 29 14:03:32 UTC 2024


> The policy name is by default AccessByAdmin. How should
> that be configured in access-controll.xml.

Brute forcing that by listing usernames should be self-evident from the examples in the file unless you don't speak Spring XML, in which case you need to learn that before anything else. We reference that in the IdP documentation early on to make it clear that's a prerequisite.

Just brute forcing names is just a demo/testing sort of approach obviously. Real world use assumes the use of attributes typically, which all admin flows can resolve if that option is enabled, and there are examples in the wiki of how to use Attribute-based rules for access control.

-- Scott




More information about the dev mailing list