<br /><span>On 22/02/12, <b class="name">&quot;Cantor, Scott&quot; </b> &lt;cantor.2@osu.edu&gt; wrote:</span><blockquote cite="mid: &lt;BA63CEAE152A7742B854C678D9491383262DDC48@CIO-KRC-D1MBX01.osuad.osu.edu" class="iwcQuote" style="border-left: 1px solid rgb(0, 0, 255); padding-left: 13px; margin-left: 0pt;" type="cite"><div class="mimepart text plain">&gt; A Query would be performed on the database using a data connector for the<br />&gt; requesting resource and values returned for all the franchises. Each<br />&gt; franchise &quot;field&quot; returned from the query would be put into an attribute<br />&gt; (FRANA_GRANTED and FRANB_GRANTED). This would then be assessed<br />&gt; along with the &quot;shibbolethset&quot; attribute to determine whether the user<br />&gt; should be given a eduPersonAffiliation attribute value which will grant access<br />&gt; to the resource.<br /><br />That's a fundamental problem. Affiliation is not based on whether you have access to a resource, it's a fact of the identity involved independent of any resource. It's a very bad idea to conflate that.<br /><br />-- Scott</div></blockquote>Hi Scott,<br />I agree, however I'm failing to see another way to accomplish the task I have been set.<br />In an ideal world I'm guessing that I would set some values for eduPersonEntitlement indicating whether the user was allowed acces to the resource and agree these with the SP's?<br />The problem I can see in this is getting all the SP's to organise and agree these within the time-frame.<br />Is there another way in which I should be attacking this?<br /><br />- Keith<br /><blockquote cite="mid: &lt;BA63CEAE152A7742B854C678D9491383262DDC48@CIO-KRC-D1MBX01.osuad.osu.edu" class="iwcQuote" style="border-left: 1px solid rgb(0, 0, 255); padding-left: 13px; margin-left: 0pt;" type="cite"><div class="mimepart text plain"><br /><br />--<br />To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br /></div></blockquote>