<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Thanks, Peter.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">I have defined a Principal Name attribute in attribute-resolver.xml and add some changes in attribute-filter.xml[IdP] and attribute-map.xml[SP]. I can see I
set attributes has already been in session scope using URL: .<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><u><span style="font-size:10.0pt;font-family:"Courier New";color:black">Miscellaneous</span></u><span style="font-size:10.0pt;font-family:"Courier New";color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:black">Session Expiration (barring inactivity):</span></b><span style="font-size:10.0pt;font-family:"Courier New";color:black"> 479 minute(s)<o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:black">Client Address:</span></b><span style="font-size:10.0pt;font-family:"Courier New";color:black"> 10.86.16.175<o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:black">SSO Protocol:</span></b><span style="font-size:10.0pt;font-family:"Courier New";color:black"> urn:oasis:names:tc:SAML:2.0:protocol<o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:black">Identity Provider:</span></b><span style="font-size:10.0pt;font-family:"Courier New";color:black"> https://idp.csrdu.org/idp/shibboleth<o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:black">Authentication Time:</span></b><span style="font-size:10.0pt;font-family:"Courier New";color:black"> 2013-04-24T06:37:12.195Z<o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:black">Authentication Context Class:</span></b><span style="font-size:10.0pt;font-family:"Courier New";color:black"> urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport<o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:black">Authentication Context Decl:</span></b><span style="font-size:10.0pt;font-family:"Courier New";color:black"> (none)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:black"><o:p> </o:p></span></p>
<p class="MsoNormal"><u><span style="font-size:10.0pt;font-family:"Courier New";color:black">Attributes</span></u><span style="font-size:10.0pt;font-family:"Courier New";color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:black">UserEmail</span></b><span style="font-size:10.0pt;font-family:"Courier New";color:black">: 1 value(s)<o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:black">priAutMet</span></b><span style="font-size:10.0pt;font-family:"Courier New";color:black">: 1 value(s)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Taking example of UserEmail attribute, I want this attribute to transfer to tomcat server behind Apache-Httpd. When program running in Tomcat gets user’s email,
it could distinguishs the what permission should be granted to.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> Peter Schober [via Shibboleth] [mailto:ml-node+<a href="/user/SendEmail.jtp?type=node&node=7586379&i=0" target="_top" rel="nofollow" link="external">[hidden email]</a>]
<br>
<b>Sent:</b> Wednesday, April 24, 2013 2:21 PM<br>
<b>To:</b> Dominic Chen<br>
<b>Subject:</b> Re: Attribute Transferring<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt">* DominicChen <<a href="/user/SendEmail.jtp?type=node&node=7586378&i=0" target="_top" rel="nofollow" link="external">[hidden email]</a>> [2013-04-24 07:30]:
<br>
> Here my question is that I want to transfer some attributes obtained in the <br>
> doPost method such as email and userId to the place where the resource.jsp <br>
> can get it. <br>
<br>
I don't no much about the ExternalAuthn login handler but generally <br>
that's only meant to identify a principal (an authenticated subject) <br>
and pass back control to the IdP. <br>
Resolving attributes for that principal generally happens at a later <br>
stage (cf. attribute-resolver.xml). <br>
<br>
If the ExternalAuthn doesn't do what you need (which I think is the <br>
case) you could still achive this with a custom login handler. There <br>
are examples in the Contributions section of the wiki. <br>
-peter <br>
-- <br>
To unsubscribe from this list send an email to <a href="/user/SendEmail.jtp?type=node&node=7586378&i=1" target="_top" rel="nofollow" link="external">
[hidden email]</a> <br>
<br>
<o:p></o:p></p>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="1" width="100%" noshade="" style="color:#CCCCCC" align="center">
</div>
<div>
<div>
<p class="MsoNormal"><b><span style="font-size:9.0pt;font-family:"Tahoma","sans-serif";color:#444444">If you reply to this email, your message will be added to the discussion below:<o:p></o:p></span></b></p>
</div>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Tahoma","sans-serif";color:#444444"><a href="http://shibboleth.1660669.n2.nabble.com/Attribute-Transferring-tp7586377p7586378.html" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/Attribute-Transferring-tp7586377p7586378.html</a>
<o:p></o:p></span></p>
</div>
<div style="margin-top:4.8pt">
<p class="MsoNormal" style="line-height:18.0pt"><span style="font-size:8.5pt;font-family:"Tahoma","sans-serif";color:#666666">To unsubscribe from Attribute Transferring,
<a href="" target="_top" rel="nofollow" link="external">
click here</a>.<br>
<a href="http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml" target="_top" rel="nofollow" link="external"><span style="font-size:7.0pt;font-family:"Times New Roman","serif"">NAML</span></a>
<o:p></o:p></span></p>
</div>
</div>
        
        
        
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/Attribute-Transferring-tp7586377p7586379.html">RE: Attribute Transferring</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">Shibboleth - Users mailing list archive</a> at Nabble.com.<br/>