Restrict attribute values based on SP entity?

Brian Mathis brian.mathis at gmail.com
Tue Nov 15 14:36:29 EST 2016


On Tue, Nov 15, 2016 at 8:16 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>> I didn't mean to imply anything about the documentation being light,
>> just that I had read what was there and needed more guidance.
>
> There's nothing to imply, it's literally non-existent. We reused the IdP's language for it but since there appeared to be little to no demand to use it, it never got documented independently. Some things are semi-obvious but a lot of things are very weird and backward when you turn "control what to release" into "control what to accept".
>
> -- Scott


I can understand your point, so are there other options for doing
something like this that doesn't involve making code changes to a
backend application, or having control of the IdP?  I'm always open to
doing things the "right" way.  But I think many people are in the
position of having control over the SSO/SP layer but not the other
parts of the system.

~ Brian


More information about the users mailing list