Administrative Logout using Attribute-Based Revocation
Cantor, Scott
cantor.2 at osu.edu
Mon Feb 10 13:25:04 UTC 2025
I doubt your service account has access to the value, but the connector would log exactly what's coming back from LDAP. The attribute definition has an option that will throw if the output value count doesn't match the input count, and if it's not doing that, there are no input values.
In either case, you'd need a formattingString that you're not providing (that's not a numeric value, it has to be parsed).
All of that is documented in the reference table.
Nor do you have any need for an encoder unless you're planning to send that out as a SSO attribute/claim.
-- Scott
More information about the users
mailing list