<div dir="ltr"><div class="gmail_extra">Thanks for the detailed response Scott.<br><br><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="im">
> Should one require that the IdPs send scoped attributes and then<br></div><div class="im">
> somehow filter out attributes that don't have the correct scope?<br>
<br>
</div>The SP filters them automatically provided the metadata allows it to do so.<br></blockquote><div><br></div><div style>What exactly in the metadata would enable that?</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
You could also rely on the NameID construct and its qualifiers and do filtering based on that, along with having flexibility in how you serialize the NameID structure into an identifier to consume.<br></blockquote><div>
<br></div><div style>Other than scope, what qualifiers of NameID would be relevant here?</div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im"><br>
> Or should<br>
> the IdPs send unscoped attributes and the SP somehow add the appropriate<br>
> scope before passing the attribute to the application?<br>
<br>
</div>It does not do that, though of course an application could.<br></blockquote><div><br></div><div style>Couldn't a Template AttributeResolver do that, or at least produce something that <b>resembles</b> a scoped attribute?<br clear="all">
<div><br></div>-- <br>Best regards,<br><br>Robert Lowe<br><a href="http://notability.rmlowe.com/" target="_blank">http://notability.rmlowe.com/</a>
<p></p>
</div></div></div></div>