Controlling IdP response status based on attribute
Christopher Bongaarts
cab at umn.edu
Wed Oct 16 14:50:11 UTC 2024
We have a vendor that doesn't do authorization on their side (yes, I
know...) A workaround they have suggested is:
> They could also independently explore that if the user is “not a
> member of the portal group” that they amend the SAML response to
> instead send a “Responder” (e.g. not “success”) status from the IdP
> which should trigger them to receive the generic Login Failed error
> message as context.
I'm wondering if there is a reasonable way to accomplish this in the IdP
(5.1.3) without too much work. We have the group membership available
as an attribute at attribute resolution time. Ideally it would be
configurable for just this SP (e.g. as their own RelyingParty
configuration).
Any suggestions on an approach?
--
%% Christopher A. Bongaarts %%cab at umn.edu %%
%% OIT - Identity Management %%http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20241016/1c04d36e/attachment.htm>
More information about the users
mailing list