Multiple values in email attribute

Cantor, Scott cantor.2 at osu.edu
Tue May 26 17:44:05 UTC 2020


Are you the IdP or the SP?

As an IdP you can do many different things, up to and including per-value consent (but which a user will probably not understand your intent/purpose since they don't *care* about your email problem caused by Amazon's bug).

As an SP, you cannot use a standard attribute like "mail" that is defined to be multiply-valued, and expect every IdP in the world to be willing to impose your preferred limitation on the syntax, even though most actual practice around it is for a single value.

-- Scott




More information about the users mailing list