IDPv3.3 and programmatically selecting MFA based on attribute
Cantor, Scott
cantor.2 at osu.edu
Tue Jan 24 10:50:37 EST 2017
> If that's my example and is what I shipped, that's my fault, all that work
> probably hadn't been tested in the context of running the logic every time
> rather than just when the first factor runs.
I did in fact botch the example, so I've committed a fix and added something to the release notes.
I've also done a pass over the material ScottK added, and I've highlighted that it can very tricky to correctly use defaultAuthenticationMethods. SPs are freely able to override that setting by simply requesting something themselves, and in a world of unsigned requests, that doesn't have to be the SP doing the overriding, it could just be the user. You can't safely use that setting to enforce MFA without additional constraints.
-- Scott
More information about the users
mailing list