PersistentSAML2NameIDGenerator requires releasing attributeSourceIds

Peter Schober peter.schober at univie.ac.at
Fri Apr 10 10:34:40 EDT 2015


* Marvin Addison <marvin.addison at gmail.com> [2015-04-10 16:07]:
> I have to admit I don't understand your justification in detail, but I
> trust you. In any case I can meet my needs by not attaching an encoder to
> the source attribute to prevent disclosure.

So if I wanted to release the source attribute to some, but to others
only the NameID generated from it? That's a very common scenario I
would guess (e.g. source attribute being uid, for those lacking a
persistent not-name-based identifier in their SORs)?
-peter


More information about the users mailing list