Using User Attributes in Context-Checks
Ritterhoff, Florian
florian.ritterhoff at hm.edu
Wed Dec 21 13:42:46 UTC 2022
Hi together,
We are currently trying to limit logins using OIDC to specified users. Therefore we initially tried to use AttributeFilterPolicies and AttributeRules. Sadly that did not work as expected due to the fact that a subject must be returned. Otherwise an error is triggered.
In a next step we stumbled over using context-checks. From our point of view using shibboleth.context-check.Condition requires to have one single check per client, the according flows and the according configuration. We would like to avoid defining several different interceptors. Is there maybe a better solution? We thought about using functions and scripts but we have no idea how to extract the user attributes using a function in this interceptor?
Kind regards
Florian Ritterhoff
--
Florian Ritterhoff - Zentrale IT
Hochschule München University of Applied Sciences
Lothstraße 34, 80335 München, G1.18C
T +49 89 1265-1745
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4670 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20221221/78120a5a/attachment.p7s>
More information about the users
mailing list