persistent nameID activation conditions for Slack Plus

Cantor, Scott cantor.2 at osu.edu
Wed Dec 5 15:05:44 EST 2018


Don't use attribute release (or even worse, NameID manipulation) to do authz for services that are broken. If you want to deny access, just do that (context-check interceptor flow).

And file a bug with the vendor since that's a broken application.
 
-- Scott




More information about the users mailing list