puzzled about the activationCondition of the AttributeReleaseFlow

Dominique Petitpierre Dominique.Petitpierre at unige.ch
Fri Jan 27 16:30:11 EST 2017


Thanks for your explanations!

Again I am puzzled, this time about your last comment:

On 01/27/2017 06:20 PM, Cantor, Scott wrote:

> The problem of consent for back channel exchanges of data, be it SAML, OAuth, or anything else, is a different sort of problem that needs different solutions than anything we have built to date.

There is a warning about this topic in the documentation:
 Attribute Release Consent / 'Note the "front-channel" caveat above.'
 https://wiki.shibboleth.net/confluence/display/IDP30/ConsentConfiguration#ConsentConfiguration-AttributeReleaseConsent

- Does that mean that for example an out of session request via the AttributeQuery handler would release attributes that were not allowed by the user? I.e. the AttributeQuery code would not take into account the attributes release decisions saved in the intercept/attribute-release context entries of the StorageRecords?
If that is the case one should prevent out of session attribute queries by filtering out the necessary persitentId/targetedId attribute for all service providers where the user is asked for attribute release consent!


--
Mr Dominique Petitpierre, user=Dominique.Petitpierre domain=unige.ch
IT Division, University of Geneva, Switzerland


More information about the users mailing list