RA21 - Resource Access for the 21st Century
Peter Schober
peter.schober at univie.ac.at
Thu Nov 30 14:35:50 EST 2017
* Rainer Hoerbe <rainer at hoerbe.at> [2017-11-30 19:38]:
> I am missing the implicit IDP-selection at provisioning time, or at
> least when logging in to a home-organization-only service.
If an arbitrary SP can load the DS (JavaScript) from a CDN (==shared
DNS domain) and persist selected IDPs to HTML5 localStorage (i.e., the
way one suggested model would work) it does not sound impossible to
load some JS on internal services (after successful authentication,
when we know a usable IDP for certain) and silently save the IDP to
HTML5 local storage, too.
Just make sure someone hears your suggestion, as that scenario might
need a slightly different code path (you don't want to pop up an IDP
selector after having just authenticated at an IDP or to an
single-IDP-only service).
-peter
More information about the users
mailing list