Docusign authorization
Paul B. Henson
henson at cpp.edu
Thu Nov 30 15:18:30 EST 2017
> From: Michael A Grady
> Sent: Wednesday, November 29, 2017 6:07 PM
>
> Perhaps you are thinking "whole new authentication flow"? In this case, the
> intercept flow is just a "post authentication flow", like consent or terms of
> use are. See this wiki page:
>
> https://wiki.shibboleth.net/confluence/display/IDP30/ContextCheckInterce
> ptConfiguration
Ah, I see; in fact the documentation for this actually says:
"A common use case for this feature is to impose authorization rules at the IdP to work around the limitations of a service that either does not implement any authorization or does not provide an adequate user experience in the event of failure."
Which is exactly what needs to be done. I also concur with the "Must be their limited budget." comment in the case of Docusign ;).
What they want though is a custom authorization denied page for this application, which I really don't want to have to maintain within the idp. Would there be an easy way to make the intercept redirect to an external webpage in the result of failure rather than displaying an internal idp error page?
Thanks much...
--
Paul B. Henson | (909) 979-6361 | http://www.cpp.edu/~henson/
Operating Systems and Network Analyst | henson at cpp.edu
California State Polytechnic University | Pomona CA 91768
More information about the users
mailing list