Access Control Rule in accessError template?
Peter Schober
peter.schober at univie.ac.at
Wed Jul 10 09:56:26 EDT 2013
* Cantor, Scott <cantor.2 at osu.edu> [2013-07-10 15:51]:
> On 7/10/13 9:38 AM, "GEANT - Lukas Hämmerle" <lukas.haemmerle at switch.ch>
> wrote:
>
> >In case of an accessError (you see if you are forbidden access due to
> >the access control rules) it is often not transparent to the user why he
> >was not allowed access to a page. Of course the template could specify
> >in prosa why access was denied. However, it could also be handy to be
> >able to have (as a parameter) the actual access control rule which Shib
> >used to determined if somebody gets access to a page or not.
> >
> >Is this somehow possible? Maybe in an undocumented parameter?
>
> I don't think so, the rules aren't labeled really, and I don't think
> anything about the failing rule is visible. The plugin returns a tristate
> (yes/no/indeterminate), and that's about it.
Also I wouldn't want my access rules to be made public, esp. on access
failure (even though they should not be exploitable simply by knowing
them it might give information away that eases another attack,
e.g. exposing userids which are allowed in, enabling targeted phishing
etc.)
-peter
More information about the users
mailing list