obtaining more granular AWS Cognito App information in shib logs?
Peter Schober
peter.schober at univie.ac.at
Thu Sep 26 11:07:56 UTC 2024
Arron Merrill via users <users at shibboleth.net> [2024-09-26 13:03 CEST]:
> We currently have numerous Cognito app integrations with our Shibboleth
> IdP. I wonder if there is a way to present information in the process logs
> about which particular app a user is attempting to access. Currently we can
> only see the entityID which belongs to the Cognito user pool
> cluster.
How would the IDP know about "apps" -- how do these differ in terms of
SAML WebSSO? If they all share an entityID the only thing left (I
think) would be ACS URLs (i.e., the endpoint the IDP sends the SAML
Reponse to) -- are these specific to those "apps"? If not there's
nothing the IDP could use to differentiate these, I think, and even
then I couldn't tell you how to put that information into your logs. ;)
-peter
More information about the users
mailing list