Attribute Transferring
DominicChen
dominic.chen at morningstar.com
Wed Apr 24 02:47:34 EDT 2013
Thanks, Peter.
I have defined a Principal Name attribute in attribute-resolver.xml and add some changes in attribute-filter.xml[IdP] and attribute-map.xml[SP]. I can see I set attributes has already been in session scope using URL: .
Miscellaneous
Session Expiration (barring inactivity): 479 minute(s)
Client Address: 10.86.16.175
SSO Protocol: urn:oasis:names:tc:SAML:2.0:protocol
Identity Provider: https://idp.csrdu.org/idp/shibboleth
Authentication Time: 2013-04-24T06:37:12.195Z
Authentication Context Class: urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
Authentication Context Decl: (none)
Attributes
UserEmail: 1 value(s)
priAutMet: 1 value(s)
Taking example of UserEmail attribute, I want this attribute to transfer to tomcat server behind Apache-Httpd. When program running in Tomcat gets user's email, it could distinguishs the what permission should be granted to.
From: Peter Schober [via Shibboleth] [mailto:ml-node+s1660669n7586378h36 at n2.nabble.com]
Sent: Wednesday, April 24, 2013 2:21 PM
To: Dominic Chen
Subject: Re: Attribute Transferring
* DominicChen <[hidden email]</user/SendEmail.jtp?type=node&node=7586378&i=0>> [2013-04-24 07:30]:
> Here my question is that I want to transfer some attributes obtained in the
> doPost method such as email and userId to the place where the resource.jsp
> can get it.
I don't no much about the ExternalAuthn login handler but generally
that's only meant to identify a principal (an authenticated subject)
and pass back control to the IdP.
Resolving attributes for that principal generally happens at a later
stage (cf. attribute-resolver.xml).
If the ExternalAuthn doesn't do what you need (which I think is the
case) you could still achive this with a custom login handler. There
are examples in the Contributions section of the wiki.
-peter
--
To unsubscribe from this list send an email to [hidden email]</user/SendEmail.jtp?type=node&node=7586378&i=1>
________________________________
If you reply to this email, your message will be added to the discussion below:
http://shibboleth.1660669.n2.nabble.com/Attribute-Transferring-tp7586377p7586378.html
To unsubscribe from Attribute Transferring, click here<http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=unsubscribe_by_code&node=7586377&code=ZG9taW5pYy5jaGVuQG1vcm5pbmdzdGFyLmNvbXw3NTg2Mzc3fDE5OTY3MjQ5ODQ=>.
NAML<http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml>
--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Attribute-Transferring-tp7586377p7586379.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130423/87b10287/attachment.html
More information about the users
mailing list