after the SOAP attribute query

David Bantz dabantz at alaska.edu
Fri Oct 24 16:16:10 EDT 2014


No a different App 2 from a different vendor:

App 1 manages local funds (“munch money” for food service and other funds).
(Thats the one that uses AttributeQuery without establishing trust out-of-band.)

App 2 is used to order and pay for items (coffee, pizza); the app shows
menu items at different locations and allows you to order in advance for 
pickup, deducting cost from the current balance in your “munch money” 
fund (or pay directly with a credit card).  
(That’s the one that solicits institutional credentials to obtain SSO and
SAML attributes “for you.”)

App 3 enables anyone to add money to your accounts managed by App 1
(self or parents add funds to your “munch money” account from a credit card).
(This one apparently lets anyone look up users in AD; the app is able to
retrieve enough data to enable a fund transfer to their accounts in App 1.)

db

On Oct 24, 2014, at 10:58, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 10/24/14, 2:15 PM, "David Bantz" <dabantz at alaska.edu> wrote:
> 
>> If that was a good start to your Friday, you¹ll appreciate the next leg
>> of the 
>> interaction.  The app that enables users to actually spend their banked $
>> on a coffee 
>> or burger solicits the user's institutional credentials directly, then
>> impersonates 
>> that user in an SSO request to the IdP; the attributes released provide
>> enough information to draw funds from the user¹s account.
> 
> This is the same app?
> 
> -- Scott



More information about the users mailing list