v3 Docs Q: Appropriate use of idp.authn.LDAP.returnAttributes?
Cantor, Scott
cantor.2 at osu.edu
Tue Jun 30 11:26:29 EDT 2015
On 6/30/15, 11:14 AM, "users on behalf of Chris Phillips" <users-bounces at shibboleth.net on behalf of Chris.Phillips at canarie.ca> wrote:
>Considering that there isn't a dataConnector written/included now leads me
>to describe best practices in this area to be:
>- Keep using attribute-resolver.xml as THE place to deal with attributes
>that appear in assertions and flows
>- When data about a subject is needed during the authentication
>(including operational attributes like password policy status etc), use
>attributes to be listed via idp.authn.LDAP.returnAttribute and defer to
>attribute-resolver.xml as THE place for attribute definition otherwise.
>- Advanced uses of idp.authn.LDAP.returnAttribute would be best served by
>a data connector that Scott describes
I certainly agree with all that. I also don't believe that the middle thing is really documented at this point, and stuff that isn't documented is basically new functionality that oughtn't to be critical to anybody during this initial upgrade period because it didn't exist before.
I don't have any problem with the idea that if it's not documented it may as well not exist, that's a perfectly fair argument. That's why I focused on documenting what was already there and not new features.
-- Scott
More information about the users
mailing list