AttributeDefinition multivalued to single value attribute?

Losen, Stephen C. (scl) scl at virginia.edu
Thu Jun 7 06:27:19 EDT 2018


Hi Baron,

You can test "someAttr" directly in the attribute filter, no need to convert it to "hasfoo-enabled".

<PolicyRequirementRule xsi:type="Value"
  AttributeID="someAttr" value="foo" />

This is true if any value of someAttr is "foo".

You can negate like this

<PolicyRequirementRule xsi:type="NOT">
  <Rule xsi:type="Value" AttributeID="someAttr" value="foo">
</PolicyRequirementRule>

This is true if none of the values of someAttr is "foo"

And you can build an arbitrarily complex rule by combining rules with xsi:type="AND" and/or xsi:type="OR"

So you might have a PolicyRequirementRule where the Requester has a particular entityID AND an attribute has a particular value.

https://wiki.shibboleth.net/confluence/display/IDP30/AttributeFilterPolicyConfiguration


Stephen C. Losen
ITS - Systems and Storage
University of Virginia
scl at virginia.edu    434-924-0640


-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Baron Fujimoto
Sent: Wednesday, June 06, 2018 10:56 PM
To: Shib Users <users at shibboleth.net>
Subject: AttributeDefinition multivalued to single value attribute?

Is there a recommended way to create an AttributeDefinition in the IdP's
attribute-resolver.xml that will map a multivalued source attribute to a
new single valued attribute?

For example, if I have the a multivalued source attribute, "someAttr" with
values as follows:

someAttr: foo
someAttr: bar
someAttr: baz

And I would like to define a new attribute, "hasFoo" which has value either
"true" or "false" depending on the value of someAttr.

If I do something like this

<resolver:AttributeDefinition xsi:type="ad:Mapped"
        id="hasFoo-enabled"
        sourceAttributeID="someAttr">

    [...]

    <!-- if someAttr is not "foo" return false -->
    <ad:DefaultValue>false</ad:DefaultValue>

    <!-- map "foo" to "true" -->
    <ad:ValueMap>
        <ad:ReturnValue>true</ad:ReturnValue>
        <ad:SourceValue ignoreCase="true">foo</ad:SourceValue>
    </ad:ValueMap>
</resolver:AttributeDefinition>

I wind up with a multivalued set of hasFoo like

hasFoo: true
hasFoo: false
hasFoo: false

But the result I really want is just a single hasFoo with value "true" if
there was a someAttr with value "foo", else hasFoo should be "false".

The broader context for this is that I would like to return the single
valued "hasFoo" in an AttributeFilterPolicy, and conditionally release
other attributes based on the value of hasFoo. Maybe there's a better
way to tackle this broader goal?

-- 
Baron Fujimoto <baron at hawaii.edu> :: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum desendus pantorum
-- 
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list