SV: Attribute Filter policy. Where am I going wrong?

Cantor, Scott cantor.2 at osu.edu
Wed Jul 29 15:55:38 EDT 2015


On 7/29/15, 3:52 PM, "users on behalf of Peter Schober" <users-bounces at shibboleth.net on behalf of peter.schober at univie.ac.at> wrote:

>* Cantor, Scott <cantor.2 at osu.edu> [2015-07-29 20:23]:
>> We might be able to enhance the syntax to handle a single child
>> (which we should have done to start with) because it's a
>> backward-compatible change (more to less strict). Feel free to file
>> an RFE. If Rod wants to shoot me for suggesting that, he can.
>
>ACK. I understand the logical correctness (or "purity") of the
>existing behaviour, I just never found it practically useful, i.e., I
>don't see the errors it would prevent by not accepting OR( 1entityID ).

No, I think it's dumb. We made a lot of mistakes like that early on. When I suggested Rod might shoot me, it was more because that code is complex and he won't want to change it and rightly so.

>(Not half the pain that groupOfNames' MUST requirement for at least
>one 'member' caused over the years; though I have dealt with in
>similar ways, i.e., add a dummy member if the last member left the
>group, in order to avoid having to delete the empty group at this
>precise moment, too.)

Eventually you learn that minOccurs must be 0, always, but you don't learn that until after screwing it up first.

-- Scott



More information about the users mailing list