OIDC claims missing after upgrade to IdP 4.1

Wessel, Keith kwessel at illinois.edu
Wed Jul 21 16:42:57 UTC 2021


Based on the XML file compiled into the jar, the default is false as the commented out value in the included properties file suggests. Explicitly setting that property to both false and true has no affect; if I include attribute release in the post-authentication flows for the oidc.sso profile results in missing claims. It wouldn't be as simple as also needing to include post-authentication in other OIDC profiles, would it? That wouldn't make sense to me since all of those other profiles are backchannel. Post-authentication and backchannel don't seem to go together, and it wasn't necessary to have attribute release as a post-authn flow for the other profiles in V2 of the OIDC extension. If you think it's worth trying, I'll tinker more. Otherwise, I'll just turn up logging, collect some more logs, and file a bug.

Thanks,
Keith


-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott
Sent: Wednesday, July 21, 2021 8:56 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: OIDC claims missing after upgrade to IdP 4.1

On 7/21/21, 9:49 AM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:

>    Are you suggesting having it set to false (default) could trigger the bug? Or if I had it set to true, that would
> trigger the bug?

Either. Whatever you did do didn't work, so plausibly trying the other way I guess might, but I wouldn't think you'd want to embed it in the tokens so if that's the default, I doubt that's involved.

-- Scott


-- 
For Consortium Member technical support, see https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!DZ3fjg!tp7DI1GE_JjBBn-ZzcFlebRoAYkJsRho12THvM-j5e9I1Evn5HT4DbxQb-0C6iQlHQ$ 
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list