<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">On 6/28/2016 7:13 AM, Rich Graves
      wrote:<br>
    </div>
    <blockquote
cite="mid:CA+Gkci3EaA-w6W+6m8i=X5BkfR2gcb2Ar14PnHLqVx21DkW2JQ@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div style="font-size:12.8px"><span style="font-size:12.8px">Disclaimer:
            I really have no idea what I'm talking about, but it seems I
            might be a half-step ahead of you.</span></div>
      </div>
    </blockquote>
    <br>
    Me neither, but a little direction can go a long ways if you're lost
    :)<br>
    <blockquote
cite="mid:CA+Gkci3EaA-w6W+6m8i=X5BkfR2gcb2Ar14PnHLqVx21DkW2JQ@mail.gmail.com"
      type="cite">
      <div dir="ltr"><span style="font-size:12.8px"> you </span><br>
        <div>
          <div style="font-size:12.8px">Look at attribute
            release/consent for inspiration. A simpler example that
            comes very close to both of your expressed needs is IDP-913,
            which is not hard to backport to 3.2.1 -- even I did it!</div>
          <div style="font-size:12.8px"><br>
          </div>
          <div style="font-size:small"><span style="font-size:12.8px"><a
                moz-do-not-send="true"
                href="https://issues.shibboleth.net/jira/browse/IDP-913"
                target="_blank"><a class="moz-txt-link-freetext" href="https://issues.shibboleth.net/jira/browse/IDP-913">https://issues.shibboleth.net/jira/browse/IDP-913</a></a></span></div>
        </div>
      </div>
    </blockquote>
    <br>
    Thanks for the pointer, this helps.  Backporting is nice in that
    someone else has already done it for you in the next release.<br>
    <br>
    <blockquote
cite="mid:CA+Gkci3EaA-w6W+6m8i=X5BkfR2gcb2Ar14PnHLqVx21DkW2JQ@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div>
          <div><span style="font-size:12.8px"></span><span
              style="font-size:12.8px">I'd be happy to share code online
              or even in person, since we're neighbors.</span></div>
        </div>
      </div>
    </blockquote>
    :)<br>
    <br>
    <blockquote
cite="mid:CA+Gkci3EaA-w6W+6m8i=X5BkfR2gcb2Ar14PnHLqVx21DkW2JQ@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div style="font-size:12.8px"><span style="font-size:12.8px">>
            Perhaps as information in a dynamic link to our pw/secrets
            app (so it has a URL to return the user to when finished)? 
            Maybe Spring has some magic that allows this?</span></div>
        <div style="font-size:12.8px"><br>
        </div>
        <div><span style="font-size:12.8px">$flowExecutionUrl&_eventId_proceed=1
            is the way back to the shibb session, but you still need to
            authenticate from shibb to your external app.</span><br>
        </div>
      </div>
    </blockquote>
    <br>
    Thanks.   The external app uses Shib for authn.<br>
    <br>
    <blockquote
cite="mid:CA+Gkci3EaA-w6W+6m8i=X5BkfR2gcb2Ar14PnHLqVx21DkW2JQ@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div style="font-size:12.8px">The "best" way to do this is
          probably to use the CAS support in shibb. Since I'm unequipped
          to do it the best way, I am looking to accomplish the handoff
          by putting Jetty behind Apache, running some stub scripts at
          the Apache layer, and communicating between the two layers
          with browser cookies. It is possible to both set and read
          cookies entirely with scripted attributes. Then you can use
          those attributes as activation conditions for minor variations
          on Context Check and Expiring Password flows.</div>
      </div>
    </blockquote>
    <br>
    This is an interesting approach - thanks for sharing it.  If it's
    not already, it might be worth adding to the shib wiki examples for
    scripted attributes as a more exotic use.<br>
    <br>
    <pre class="moz-signature" cols="72">-- 
%%  Christopher A. Bongaarts   %%  <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a>          %%
%%  OIT - Identity Management  %%  <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a>  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%
</pre>
  </body>
</html>