Deny attribute release to federated Service Provider for specific users.

Rod Widdowson rdw at steadingsoftware.com
Wed Feb 4 05:57:25 EST 2015


 
> The thought is to put the deny rules in attribute-filter.xml so users with
the
> specific attribute value don't have other attributes release while users
without
> the specific attribute value get all of their attributes released based on
what is
> in the federations attribute filter file.   Is this workable?  

It should be.

> Can you specify the
> precedence of which attribute filter file is used first?

It shouldn't matter, all rules are always run and deny anywhere will always
trump an allow.

I'd suggest that you  run with
edu.internet2.middleware.shibboleth.common.attribute.filter (V2) or
net.shibboleth.idp.attribute.filter (V3) at DEBUG to see this happening.




More information about the users mailing list