<div dir="ltr"><div class="gmail_default" style="font-family:'trebuchet ms',sans-serif;color:rgb(68,68,68)"><div class="gmail_default" style="font-size:12.8px">Good evening all-</div><div class="gmail_default" style="font-size:12.8px"><br></div><div class="gmail_default" style="font-size:12.8px">I've been subscribed to the Shib users list for about a year now and have learned a tremendous amount by reading the conversations hosted here. Thanks to all who participate and contribute - I'm writing to ask your advice:</div><div class="gmail_default" style="font-size:12.8px"><br></div><div class="gmail_default" style="font-size:12.8px">We're in the very early stages of a rebuild of our University intranet platform. Until about 6 months ago (when we deployed Shibboleth), the existing system also handled some semblance of an SSO system for our web resources. Because this system was "home brew", the previous administrators had used it to effectively intercept certain users upon login for a variety of reasons - data collection, account restrictions, notifications, etc - and redirect those users to a specified URL prior to their original destination. Whether the idea of impeding access to our web resources is a good one or not, it's become part of the business rules we live by and a fair few processes have become dependent on that ability.</div><div class="gmail_default" style="font-size:12.8px"><br></div><div class="gmail_default" style="font-size:12.8px">To make a long story short, removing the authentication role from our intranet rendered our existing "block code" system somewhat ineffective, and we're hoping to move a small portion of this to our Shib deployment. </div><div class="gmail_default" style="font-size:12.8px"><br></div><div class="gmail_default" style="font-size:12.8px"><span style="font-size:12.8px">In an ideal scenario, after successfully authenticating a user, the IDP would query our block-code api, with the user's distinct name or id number, and receive a response indicating whether the user should be 'intercepted' - and if so, to what forwarding address they should be sent. The "intercepting" address should also be given some indication of the user's original destination, so that once they've completed whatever task is blocking their access, they can be redirected. </span><br></div><div class="gmail_default" style="font-size:12.8px"><br></div><div class="gmail_default" style="font-size:12.8px">I recall reading something on this list about post-authentication workflows (similar to how attribute consent works?) but can't seem to locate documentation that describes this in a way that correlates in my head to what I'm looking to do.</div><div class="gmail_default" style="font-size:12.8px"><br></div><div class="gmail_default" style="font-size:12.8px">In short:</div><div class="gmail_default" style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:12.8px"><ol><li style="margin-left:15px"><font color="#444444" face="trebuchet ms, sans-serif">Is the IDP the correct place to attempt this? Or am I barking up the wrong tree?</font></li><li style="margin-left:15px"><font color="#444444" face="trebuchet ms, sans-serif">Is 'post-authentication workflow' what I'm looking for here, and if so, is that the correct terminology to be researching?</font></li><li style="margin-left:15px"><font color="#444444" face="trebuchet ms, sans-serif">Does anyone have any experience implementing something along these lines, and have any suggestions/feedback/"gotchas" to share?</font></li></ol><div><font color="#444444" face="trebuchet ms, sans-serif">Apologies if I've overlooked obvious documentation on the subject - I promise I've made a good faith effort to RTFM. :)</font></div><div><font color="#444444" face="trebuchet ms, sans-serif"><br></font></div><div><font color="#444444" face="trebuchet ms, sans-serif">Thanks in advance,</font></div><div><font color="#444444" face="trebuchet ms, sans-serif">Aaron</font></div><div><font color="#444444" face="trebuchet ms, sans-serif"><br></font></div><div><font color="#444444" face="trebuchet ms, sans-serif"><br></font></div></div></div><div><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div style="color:rgb(80,0,80)"><span style="color:rgb(68,68,68);font-family:'arial black',sans-serif;font-size:small">Aaron Cargo</span><br></div><div style="color:rgb(80,0,80)"><i><font color="#666666" face="trebuchet ms, sans-serif">Senior Web Developer</font></i></div><div style="color:rgb(80,0,80)"><font face="trebuchet ms, sans-serif" color="#666666">Seton Hill University</font></div><div style="color:rgb(80,0,80)"><font color="#666666"><font face="trebuchet ms, sans-serif"><a href="mailto:acargo@setonhill.edu" style="color:rgb(17,85,204)" target="_blank">acargo@setonhill.edu</a></font></font></div><div style="color:rgb(80,0,80)"><font color="#666666"><font face="trebuchet ms, sans-serif">(</font><font face="trebuchet ms, sans-serif">724</font><font face="trebuchet ms, sans-serif">)</font><font face="trebuchet ms, sans-serif"> 552</font><font face="trebuchet ms, sans-serif">-</font><font face="trebuchet ms, sans-serif">4386</font></font></div><div style="color:rgb(80,0,80)"><br></div><div style="color:rgb(80,0,80)"><img src="http://img.setonhill.edu/MLwL.png" width="96" height="58"></div><br></div></div></div></div></div>
</div>