<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Tue, Jun 30, 2015 at 9:38 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 6/29/15, 10:58 PM, "users on behalf of Daniel Fisher" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:dfisher@vt.edu">dfisher@vt.edu</a>> wrote:<br>
><br>
>One reason to pull attributes during authentication is that it is the only time you can read attributes as the authenticating user. For some directory implementations it is attractive to simply exercise the user ACLs rather than configuring a service account to read that data.<br>
<br>
</span>While that's true, it isn't as simple to punt everything the data connector does over to this step.</blockquote><div><br></div><div>I didn't mean to suggest that, just that I see some potential problems being solved here. The primary intent was indeed exposing data to the authentication flow.</div><div><br></div><div>--Daniel Fisher</div><div><br></div></div></div></div>