force login failure based on attribute value
Klingenstein, Nate
nklingenstein at calstate.edu
Wed Jun 13 16:02:49 EDT 2018
Juan,
Yes, it's possible. The easiest way is to write a ContextCheckIntercept with a check for that attribute with that value exposed by the attribute resolver.
https://wiki.shibboleth.net/confluence/display/IDP30/ContextCheckInterceptConfiguration
The example configuration should be directly helpful for you.
Hope this helps too,
Nate.
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Juan Padilla <juan.padilla at nxp.com>
Sent: Wednesday, June 13, 2018 12:56:16 PM
To: users at shibboleth.net
Subject: force login failure based on attribute value
Is there a way to add logic in attribute-resolver (or other method) to not send the user back to the SP on successful login if an attribute is a certain value?
For example, if user is not part of an ldap group then send to an error page instead of the service provider.
Thanks.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180613/2178fd0e/attachment.html>
More information about the users
mailing list