missing attributes in output from idpv3 /cas/serviceValidate

Cantor, Scott cantor.2 at osu.edu
Wed Apr 6 20:36:30 EDT 2016

On 4/6/16, 8:22 PM, "users on behalf of Paul B. Henson" <users-bounces at shibboleth.net on behalf of henson at cpp.edu> wrote:

>So the attributes are getting released, but for some reason the
>serviceValidate endpoint isn't including them? Should I open a bug? Or
>is there possibly something wrong with my configuration? I don't see how
>I could have a configuration that works for samlValidate but not
>serviceValidate but who knows :).

I don't see any obvious explanation for that in the code, doesn't seem possible. For one thing, it checks for a null AttributeContext and throws. So there absolutely cannot be any attributes in that context.

Are you sure that filtering evidence is from the serviceValidate step and not a /login step? My read is that it should be resolving/filtering twice, once for /login and then once for the /serviceValidate...

-- Scott

