Controlling IdP response status based on attribute

Christopher Bongaarts cab at umn.edu
Wed Oct 16 14:50:11 UTC 2024


We have a vendor that doesn't do authorization on their side (yes, I 
know...) A workaround they have suggested is:

> They could also independently explore that if the user is “not a 
> member of the portal group” that they amend the SAML response to 
> instead send a “Responder” (e.g. not “success”) status from the IdP 
> which should trigger them to receive the generic Login Failed error 
> message as context.

I'm wondering if there is a reasonable way to accomplish this in the IdP 
(5.1.3) without too much work.  We have the group membership available 
as an attribute at attribute resolution time.  Ideally it would be 
configurable for just this SP (e.g. as their own RelyingParty 
configuration).

Any suggestions on an approach?

-- 
%%  Christopher A. Bongaarts   %%cab at umn.edu          %%
%%  OIT - Identity Management  %%http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20241016/1c04d36e/attachment.htm>


More information about the users mailing list