Better approach to do Authorization in shibboleth
Surinaidu Majji
pioneer.suri at gmail.com
Tue Dec 2 06:59:25 EST 2014
Hello Cantor,
Thank you for your reply, but you are saying attributes pulled from
resolver:
Is that attribute-resolver.xml, configured for releasing attributes, in
that case
i am releasing 'principal' which contains 'permissions' to SP. Is that
right?
On Mon, Dec 1, 2014 at 8:36 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 12/1/14, 10:03 AM, "Surinaidu Majji" <pioneer.suri at gmail.com> wrote:
>
> >The above is the authentication process we are following for our
> >application, Now we wanted to do the authorization, So i need two
> >clarifications here.
> >i) Do i need to prepare one more samlRequest like SAML Authorization
> >Decision statement to send for idp again after authentication is done.
>
> No.
>
> >or
> >
> >ii) As i mentioned in the step(2), Shall i get the authorization
> >permission from our server and put it in the(login.getAttributes()) which
> >is in the UserPrinciple(), to get it at the SP side and use the
> >permissions to give the access to the user.
>
> No.
>
> Peter answered your question several times.
>
> Attributes are pulled from the resolver and encoded into the SSO assertion
> and it's up to the SP to get them out and use them.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141202/7b68107b/attachment.html
More information about the users
mailing list