revoking consent when proxying auth to other IDP

Martin Hitschel Martin.Hitschel at DAASI.de
Wed Sep 6 15:28:36 UTC 2023


Hi,

I'd like to resurrect this thread since we've been asked about this
feature by a customer that has introduced proxying just now.

Actually I would say this needs to be put on
https://idp.example.org/idp/profile/user/prefs

And in my opinion it would suffice to save a clear_consent_cookie, just
like with SPNEGO, there.

When the user ticks that cookies's check box, they will see the consent
page upon next log-in.

I think that would be way less work to implement than pulling consent
values from their hashes out of the Storage.

Cheers

Martin



On 01.08.23 21:14, Cantor, Scott via users wrote:
>> A "user profile page" showing your previously accessed services and
>> the attributes released to them (however you would find it) would of
>> course be the perfect place to click a few "X"s to revoke some of
>> those decisions.
> I have a hard time really believing users will find it or use
> somethiing like that, but in isolation I don't have a better idea.
>
>> Well, the question of where to put such an UI and how would subjects
>> find it was posed by Mihály on the REFEDS list earlier this year:
> I vaguely recall, but your suggestion to raise it on any of our lists
> was not to my knowledge taken up, so I'm unaware of the work beyond
> that point.
>
> FWIW, the hello world page in the IdP is more or less how this would
> be done. It's an administrative flow, essentially. And yes, the
> hardest part by far would be pulling in consent data.
>
> -- Scott
>
>
-- 
Dr. Martin Hitschel, Senior Consultant

DAASI International
Europaplatz 3                   
D-72072 Tübingen                
Germany                    

phone: +49 7071 407109-0
fax:   +49 7071 407109-9  
email: martin.hitschel at daasi.de
web:   www.daasi.de

Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz



More information about the users mailing list