Best practice MFA IdP3.3.1

O'Dowd, Josh Josh.O'Dowd at mso.umt.edu
Fri Sep 15 18:07:13 EDT 2017


> It's one of those things that sort of demands a certain amount of either trust or investigating to see that it's doing the right thing, whereas just directly screwing with the AttributeContext is certainly "safer" in the sense that you know exactly what you're getting rid of.

I'll just go with an "AttributeManipulation" action in the interceptor.  This is all just to accommodate some legacy services and bad directory data schema practices that we are working to move on from so eventually I will strip this back out of the IdP.  Probably better to keep it encapsulated in an interceptor.  My problem all along was thinking that the interceptors run before attribute-filtering.

Thanks for the help.

Josh


More information about the users mailing list