how would we suggest improving the user experience at this SP

Steven Carmody steven_carmody at brown.edu
Wed Jun 4 10:57:10 EDT 2014


Hi,

I've been trying to use a Shib-enabled SP, and I've been having some 
problems. I'm wondering if this group might provide some "best practice" 
info addressing some of the issues that I encountered. I'd prefer to not 
identify the site. Rather, I think the problems I encountered may be 
evident on lots of sites, and are more general than just this one site.

I went to the public front page, and clicked a button. This transferred 
me to a variation of the Discovery Service implementation provided by 
the Shib project. I selected my campus, and was transferred to my IDP. 
(Note -- my login page did display the Description text for this SP; 
however, the logo url in the metadata element for this SP was stale.)

I was then presented with an error page:

 > There seems to be a problem with your account.
 > We have not received your email address from your identity provider 
(IdP). This might be because your home organization IdP is not releasing
your email address.
 > Please see your home organization's IdP administrator. See our
Attribute Release Policy for more information.

I'd like to identify some of the issues I encountered, and see if there 
are suggestions:

1) This site is a member of InCommon, and is clearly supporting Higher 
Ed Identity issues, but for unknown reasons this is NOT an R&S site. If 
it were, my IDP would have released the desired attributes.

2) This seems to be a "big" SP hosting many services, which may explain 
why no R&S. I'm told that all of the services require the same 
attributes, tho. What might prevent this site from being tagged as R&S ?

3) There was no indication up front during the Login process that 
attributes are requested or required. Where should that have been done ?

4) There was no indication of the SP's entityID value. My IDP admin 
needs that value in order to construct an Attribute Release Filter.

5) The site did not follow InCommon's recommended error handling 
recommendations:

https://spaces.internet2.edu/display/InCFederation/Federated+Error+Handling

Instead, I was presented with this page containing this text:

     We have not received your email address from your identity provider 
(IdP). This might be because your home organization IdP is not releasing 
your email address.

Interestingly, this text does not agree with the RequestedAttribute 
elements in the metadata entry.

6) That error page contains a dead link to attribute policy.

     We're sorry. It appears that something has broken on our system. 
Don't worry, the web support team has been notified and will fix this 
issue as soon as possible.

7) If I retry the whole process, I am immediately redirected to the main 
web page for the site. No Discovery Service, no IDP. I understand that. 
But, instead of seeing an error, I'm redirected to a useless url.

What should it do ?

thanks for any and all suggestions !


More information about the users mailing list