Lazy sessions and authorization (Drupal)

Cantor, Scott cantor.2 at osu.edu
Tue Nov 5 12:00:15 EST 2013


On 11/5/13, 11:10 AM, "Christopher Bongaarts" <cab at umn.edu> wrote:

>On 11/4/2013 2:31 PM, Laas Toom wrote:
>> I named it bad. What I meant was ³Do not set ENV variables if not
>>authorized² - essentially kicking the second group into being
>>unauthenticated as far as this app is concerned.
>
>I wonder if the attribute filtering in the SP could be (ab)used to
>accomplish this...

Possibly, but I doubt it would be less work than the attribute checker,
and they would have similar limitations in terms of when it would happen.

-- Scott




More information about the users mailing list