library-walk-in

Cantor, Scott cantor.2 at osu.edu
Tue Feb 26 14:49:54 EST 2019


On 2/26/19, 2:42 PM, "users on behalf of Peter Schober" <users-bounces at shibboleth.net on behalf of peter.schober at univie.ac.at> wrote:

> Well, I had the feel that having an essentially self-contained
> AttributeFilterPolicy dealing with this one specific case-case
> (walk-in user surrogate) would be much cleaner than infecting
> potentially each and every AttributeDefinition in the resolver with
> special-case custom references to "notLibraryWalkIn" (where it's
> convievable that some filter rule may release the attribute).

I was imagining it mainly at the DataConnector layer as long as things are configured to gracefully handle the null cases (or you could supply alternative connectors as failovers that supply the specific static data for that identity).

Anyway, the main point was, if the NameID layer has no data to depend on, it won't run and doesn't need to be told not to.

-- Scott




More information about the users mailing list