IdPv3 RP Override Additivity

Cantor, Scott cantor.2 at
Fri May 22 17:06:28 EDT 2015

On 5/22/15, 4:48 PM, "Marvin Addison" <marvin.addison at> wrote:

>Let's say that there are several relying party overrides whose match condition is satisfied by a request; which one(s) apply? I'm hoping all of them in some kind of additive fashion instead of first or last one wins. I don't see that discussed on RelyingPartyConfiguration.

It's always been first match only, there's no merging.

>If it matters, I would like to use this facility to set the responder ID for requests coming in from a particular metadata group, while still having existing relying party overrides fire according to more specific match criteria.

The best way to do that in V3 (which V2 couldn't do) is with bean inheritance to combine settings. It's not 100% the same but it adresses a lot of the common use cases for merging by putting common settings in a parent bean.

I think we talkd about this on the list a few weeks back.

