SP Authorization via ContextCheckPredicate

Cantor, Scott cantor.2 at osu.edu
Mon Jun 26 19:33:58 EDT 2017


On 6/26/17, 6:09 PM, "users on behalf of Jann Malenkoff" <users-bounces at shibboleth.net on behalf of jannmalenkoff at gmail.com> wrote:

> Following on earlier threads on the mailing list from 
> Feb 13, 2017 -- is the below suitable on how we can restrict users to an SP based on presence of 2 isMemberOf groups and an
> eduPersonEntitlement?

I can't answer that since I don't know exactly what you think that means. The javadoc for the class (net.shibboleth.idp.profile.logic.SimpleAttributePredicate) explains in some precision how it works, so that's your answer in combination with the exact policy you're trying to apply.

-- Scott




More information about the users mailing list