force login failure based on attribute value

Klingenstein, Nate nklingenstein at calstate.edu
Wed Jun 13 16:02:49 EDT 2018


Juan,


Yes, it's possible.  The easiest way is to write a ContextCheckIntercept with a check for that attribute with that value exposed by the attribute resolver.


https://wiki.shibboleth.net/confluence/display/IDP30/ContextCheckInterceptConfiguration


The example configuration should be directly helpful for you.

Hope this helps too,

Nate.

________________________________
From: users <users-bounces at shibboleth.net> on behalf of Juan Padilla <juan.padilla at nxp.com>
Sent: Wednesday, June 13, 2018 12:56:16 PM
To: users at shibboleth.net
Subject: force login failure based on attribute value


Is there a way to add logic in attribute-resolver (or other method) to not send the user back to the SP on successful login if an attribute is a certain value?



For example, if user is not part of an ldap group then send to an error page instead of the service provider.



Thanks.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180613/2178fd0e/attachment.html>


More information about the users mailing list