Two endpoints, same entityID, different attribute filter?

Eric Hattemer ehatteme at usc.edu
Tue Feb 7 15:35:58 EST 2017


On 02/07/2017 03:46 AM, Peter Schober wrote:
> * Eric Hattemer <ehatteme at usc.edu> [2017-02-07 04:53]:
>> I'd like the response URL to trigger a specific set of attribute
>> release rules, in case we need to serve two different populations
>> for Marketo (it isn't campus-wide).
> I'm guessing you'd want to release the minimum set of attributes the
> service needs in order to function. Why would that set differ for two
> populations?

It's the populations themselves that matter, not the attributes.  Maybe
there's a better way to do it, but normally we control access to a
service by a <PolicyRequirementRule> with a group entitlement.  Imagine
we made two groups and put them both in the same
<AttributeFilterPolicy>.  They have two different ACS Locations that go
to two completely different environments, owned by two different
schools.  Now one school can go into our group management system and add
people to their group, and suddenly those people have access to the
other school's instance.  They may not know they have access to both
school's instances, and they would have to know about the other school's
URL, but it still seems like a security issue to me.

-Eric Hattemer




More information about the users mailing list