Adding a post authentication flow to an SP using metadata-driven configuration
Ullfig, Roberto Alfredo
rullfig at uic.edu
Fri Apr 7 18:46:57 UTC 2023
This is a problem for us now. We can't go into InCommon's metadata and enable attribute-release for all the SPs we release attributes to but we still want to use SAML2.SSO.MDDriven.
---
Roberto Ullfig - rullfig at uic.edu
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Wessel, Keith <kwessel at illinois.edu>
Sent: Tuesday, October 12, 2021 7:23 AM
To: Shib Users <users at shibboleth.net>
Subject: RE: Adding a post authentication flow to an SP using metadata-driven configuration
Thanks, Scott. I think that makes sense though I would have expected the order to be reversed so I could, as I said, set defaults then override them with metadata. In this case, though, it's no problem for me to set all that I need to set with metadata.
Keith
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott
Sent: Tuesday, October 12, 2021 7:17 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: Adding a post authentication flow to an SP using metadata-driven configuration
On 10/11/21, 9:31 PM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:
> Is this intentional? Or should I be able to set a default and
> override it with metadata-driven settings? I can always set my default using metadata-driven settings, too, if need be.
It's intentional. There's a layering of beans, and setting the property explicitly replaces the metadata-based lookup function with a "constant" lookup function that returns the values you set. The reason being that it lets you do exactly that: use metadata for lots of stuff but then override things you want to set explicitly inline. The fact that there's a predictable order to it is intentional and a feature.
-- Scott
--
For Consortium Member technical support, see https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.com%2Fv3%2F__https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw__%3B!!DZ3fjg!uSHb3ONUIgsBryAS8BiE9nQY-v29LIV_P0nNspjMNJit7zRvxAJMFXgB-3JDnRBRJQ%24&data=04%7C01%7Crullfig%40uic.edu%7C5500717c3ddd4feed7f208d98d7b21be%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637696382861379983%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=TMRgbAHM4SIcDS%2B%2FqFkSqu4sOhWoDuFAZn9hk5C3P0s%3D&reserved=0<https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!DZ3fjg!uSHb3ONUIgsBryAS8BiE9nQY-v29LIV_P0nNspjMNJit7zRvxAJMFXgB-3JDnRBRJQ$>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
For Consortium Member technical support, see https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=04%7C01%7Crullfig%40uic.edu%7C5500717c3ddd4feed7f208d98d7b21be%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637696382861389939%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=yLKmypJlpkvij1LhMzolwaSXZ8TNxJg10y4CgopBApM%3D&reserved=0<https://shibboleth.atlassian.net/wiki/x/ZYEpPw>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230407/56da34f0/attachment.htm>
More information about the users
mailing list