<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Helvetica;
        panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0cm;
        margin-right:0cm;
        margin-bottom:0cm;
        margin-left:36.0pt;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:538930309;
        mso-list-type:hybrid;
        mso-list-template-ids:-595922016 336134145 336134147 336134149 336134145 336134147 336134149 336134145 336134147 336134149;}
@list l0:level1
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:Symbol;}
@list l0:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:"Courier New";}
@list l0:level3
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:Wingdings;}
@list l0:level4
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:Symbol;}
@list l0:level5
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:"Courier New";}
@list l0:level6
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:Wingdings;}
@list l0:level7
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:Symbol;}
@list l0:level8
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:"Courier New";}
@list l0:level9
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:Wingdings;}
ol
        {margin-bottom:0cm;}
ul
        {margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-NZ" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hi all, I have implemented some ContextCheck intercepts[2] for some major typical use-cases / headaches we have (eg. only users from a certain campus); we also have the IdP in question integrating with another SSO system using RemoteUserAuth[2]<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">[1] <a href="https://wiki.shibboleth.net/confluence/display/IDP30/ContextCheckInterceptConfiguration">
https://wiki.shibboleth.net/confluence/display/IDP30/ContextCheckInterceptConfiguration</a><o:p></o:p></p>
<p class="MsoNormal">[2] <a href="https://wiki.shibboleth.net/confluence/display/IDP30/RemoteUserAuthnConfiguration">
https://wiki.shibboleth.net/confluence/display/IDP30/RemoteUserAuthnConfiguration</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I would like to be able to include in error.vm the following information, which would be of inestimable value for triaging faults for the Service Desk:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoListParagraph" style="text-indent:-18.0pt;mso-list:l0 level1 lfo1"><![if !supportLists]><span style="font-family:Symbol"><span style="mso-list:Ignore">·<span style="font:7.0pt "Times New Roman"">        
</span></span></span><![endif]>The user (if any) that was logged in (in case the user was logged in using an account they did not expect)<o:p></o:p></p>
<p class="MsoListParagraph" style="text-indent:-18.0pt;mso-list:l0 level1 lfo1"><![if !supportLists]><span style="font-family:Symbol"><span style="mso-list:Ignore">·<span style="font:7.0pt "Times New Roman"">        
</span></span></span><![endif]>The serviceName of the Relying Party in question – what I’m currently working on.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">With the assistance of the documentation on VelocityVariables[3], I’ve managed to get a nice, branded views/error.vm, but one that only has a subset of the information I would like to surface.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">[3] <a href="https://wiki.shibboleth.net/confluence/display/IDP30/VelocityVariables">
https://wiki.shibboleth.net/confluence/display/IDP30/VelocityVariables</a> <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">(I might also mention that this is templated using Ansible in my deployment)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">    #if ($eventId == "AccessDenied" or $eventId == "ContextCheckDenied"<o:p></o:p></p>
<p class="MsoNormal">         or $eventId == "FailedRequirement_for_library_electronic_resources_users"<o:p></o:p></p>
<p class="MsoNormal">         or $eventId == "FailedRequirement_for_wellington_campus_only"<o:p></o:p></p>
<p class="MsoNormal">         )<o:p></o:p></p>
<p class="MsoNormal">    ## Added in an attempt to get a rpUIContext, but not quite there<o:p></o:p></p>
<p class="MsoNormal">    #set ($rpContext = $profileRequestContext.getSubcontext('net.shibboleth.idp.profile.context.RelyingPartyContext'))<o:p></o:p></p>
<p class="MsoNormal">        $response.setStatus(403)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">And the following HTML<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">            <div style="font-weight: bold"><o:p></o:p></p>
<p class="MsoNormal">            #evaluate($message)<o:p></o:p></p>
<p class="MsoNormal">            </div><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">            <div><o:p></o:p></p>
<p class="MsoNormal">              <p>Please report the following additional information if submitting a Service Desk request.</p><o:p></o:p></p>
<p class="MsoNormal">              <p>Service Provider ID: $encoder.encodeForHTML($rpContext.relyingPartyId)<p><o:p></o:p></p>
<p class="MsoNormal">            </div><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">And the user sees something like the following (my development environment is an SP in a vagrant box):<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="text-indent:36.0pt"><span style="font-size:10.5pt;font-family:"Helvetica",sans-serif;color:#444444;background:white">Service Provider ID:
<a href="https://siteA.192.168.33.10.xip.io/shibboleth">https://siteA.192.168.33.10.xip.io/shibboleth</a><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">As you can see, I could dig out the rpContext, but I can’t figure out how to get the rpUIContext[4] which would give me a (potentially) friendlier / more user-recognisable name.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">[4] <a href="https://wiki.shibboleth.net/confluence/display/IDP30/RpUIContext">
https://wiki.shibboleth.net/confluence/display/IDP30/RpUIContext</a> <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Grepping around, I saw in logout.vm something that set rpUIContext, so tried this:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">    #set ($rpUIContext = $rpContext.getSubcontext("net.shibboleth.idp.ui.context.RelyingPartyUIContext"))<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">But the following doesn’t seem to encode to anything:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">                $encoder.encodeForHTML($rpUIContext.getServiceName())<o:p></o:p></p>
<p class="MsoNormal">                $encoder.encodeForHTML($rpUIContext.serviceName)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Grepping further, I’m thinking that I’m on the right path, but wondering if I need to add something to my –flow.xml file, like what I see in the terms-of-use context-check.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I tried the following in my ${IDP_HOME}/flows/intercept/wellington_campus_only/wellington_campus_only-flow.xml  file, somewhat blindly duplicating what I found in ${IDP_HOME}/system/flows/intercept/terms-of-use-flow.xml:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><?xml version="1.0" encoding="UTF-8"?><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><!--<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">  Ansible managed<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">--><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><flow xmlns="http://www.springframework.org/schema/webflow"<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">      xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">      xsi:schemaLocation="http://www.springframework.org/schema/webflow http://www.springframework.org/schema/webflow/spring-webflow.xsd"<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">      parent="intercept.abstract"><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">    <action-state id="ContextCheckSetup">  <!-- I added this node --><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">       <evaluate expression="SetRPUIInformation" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">    </action-state><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">    <decision-state id="CheckContext"><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">        <if test="ContextCheckPredicate.apply(opensamlProfileRequestContext)"<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">            then="proceed" else="FailedRequirement_for_wellington_campus_only" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">    </decision-state><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">    <view-state id=" FailedRequirement_for_wellington_campus_only " view="#{flowRequestContext.activeFlow.id}">  <!-- I added this node, had to play with this to figure out that the ‘id’ should be the name of
 a state, I think  --><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">        <on-render><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">            <evaluate expression="SetRPUIInformation.getRPUIContextCreateStrategy().apply(opensamlProfileRequestContext)" result="viewScope.rpUIContext"/><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">        </on-render><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">    </view-state><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">    <bean-import resource="wellington_campus_only-beans.xml" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"></flow><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">… and through chasing error-messages and grepping, added this to the matching –beans.xml file:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">    <bean id="SetRPUIInformation"<o:p></o:p></p>
<p class="MsoNormal">            class="net.shibboleth.idp.ui.impl.SetRPUIInformation" scope="prototype"<o:p></o:p></p>
<p class="MsoNormal">            p:httpServletRequest-ref="shibboleth.HttpServletRequest"><o:p></o:p></p>
<p class="MsoNormal">        <property name="fallbackLanguages"><o:p></o:p></p>
<p class="MsoNormal">            <bean parent="shibboleth.CommaDelimStringArray" c:_0="#{'%{idp.ui.fallbackLanguages:}'.trim()}" /><o:p></o:p></p>
<p class="MsoNormal">        </property><o:p></o:p></p>
<p class="MsoNormal">    </bean><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">And now I’m up  to the following error, presumably because what I would *<b>like</b>* to do is to add something to a view, but what I *<b>think</b>* I’m doing is actually creating a view (which has been automatically created as an end-state
 via conf/errors.xml)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">2017-02-27 12:36:24,308 - ERROR [net.shibboleth.idp.profile.interceptor:-2] - Uncaught runtime exception<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">java.lang.IllegalArgumentException: This flow 'intercept/wellington_campus_only' already contains a state with id 'FailedRequirement_for_wellington_campus_only' -- state ids must be locally unique to the flow
 definition; existing state-ids of this flow include: array<String>['ContextCheckSetup', 'CheckContext', 'FailedRequirement_for_wellington_campus_only', 'proceed', 'InvalidProfileContext', 'MessageExpired', 'MessageReplay', 'MessageAuthenticationError', 'AttributeReleaseRejected',
 'TermsRejected', 'ContextCheckDenied', 'RuntimeException', 'LogRuntimeException'']<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">                at org.springframework.webflow.engine.Flow.add(Flow.java:256)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">This is my first foray into Spring Web Flow, so if anyone can help, I’d greatly appreciate it. I’ve tried moving the on-render and evaluate to different places, but just end up breaking XML validation.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Many thanks!<o:p></o:p></p>
<p class="MsoNormal">Cameron<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" style="border-collapse:collapse">
<tbody>
<tr style="height:15.95pt">
<td width="397" colspan="2" valign="top" style="width:297.4pt;border:solid #B2A1C7 1.0pt;padding:2.9pt 5.75pt 2.9pt 5.75pt;height:15.95pt">
<p class="MsoNormal" style="line-height:105%"><b><span lang="ES-CO" style="font-size:10.0pt;line-height:105%;color:#1F497D;text-transform:uppercase;letter-spacing:.2pt;mso-fareast-language:EN-NZ">Cameron Kerr</span></b><span style="mso-fareast-language:EN-NZ"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:105%"><b><span lang="ES-CO" style="font-size:8.0pt;line-height:105%;color:#365F91;text-transform:uppercase;letter-spacing:1.0pt;mso-fareast-language:EN-NZ">systems Engineer</span></b><span style="mso-fareast-language:EN-NZ"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:105%"><span style="font-size:7.5pt;line-height:105%;color:#1F497D;text-transform:uppercase;letter-spacing:1.0pt;mso-fareast-language:EN-NZ">Infrastructure & applications its</span><span style="mso-fareast-language:EN-NZ"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:105%"><span style="font-size:7.5pt;line-height:105%;color:#1F497D;text-transform:uppercase;letter-spacing:1.0pt;mso-fareast-language:EN-NZ">university of otago</span><span style="mso-fareast-language:EN-NZ"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:105%"><span lang="ES-CO" style="font-size:8.0pt;line-height:105%;color:#1F497D;mso-fareast-language:EN-NZ">T: +64 3 479 8191 | M: +64 021 479 527 </span><span style="mso-fareast-language:EN-NZ"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:105%"><span lang="FR" style="font-size:8.0pt;line-height:105%;color:#1F497D;mso-fareast-language:EN-NZ">E   :
</span><span lang="FR" style="font-size:8.0pt;line-height:105%;color:#2E74B5;mso-fareast-language:EN-NZ"><a href="mailto:cameron.kerr@otago.ac.nz"><span style="color:#2E74B5">cameron.kerr@otago.ac.nz</span></a></span><span style="mso-fareast-language:EN-NZ"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:1.0pt;line-height:105%"><span lang="FR" style="font-size:8.0pt;line-height:105%;color:#1F497D;mso-fareast-language:EN-NZ">W :
</span><span lang="FR" style="font-size:8.0pt;line-height:105%;color:#2E74B5;mso-fareast-language:EN-NZ"><a href="http://www.otago.ac.nz/its"><span style="color:#2E74B5">www.otago.ac.nz/its</span></a></span><span lang="FR" style="font-size:8.0pt;line-height:105%;color:#1F497D;mso-fareast-language:EN-NZ">
</span><span style="mso-fareast-language:EN-NZ"><o:p></o:p></span></p>
</td>
</tr>
<tr style="height:1.2pt">
<td width="16" valign="top" style="width:11.8pt;border:solid #B2A1C7 1.0pt;border-top:none;background:#CCC0D9;padding:2.9pt 5.75pt 2.9pt 5.75pt;height:1.2pt">
</td>
<td width="381" valign="top" style="width:285.6pt;border-top:none;border-left:none;border-bottom:solid #B2A1C7 1.0pt;border-right:solid #B2A1C7 1.0pt;padding:2.9pt 5.75pt 2.9pt 5.75pt;height:1.2pt">
<p class="MsoNormal" style="mso-line-height-alt:1.1pt"><span lang="ES-CO" style="font-size:8.0pt;color:#1F497D;letter-spacing:1.0pt;mso-fareast-language:EN-NZ">Te Wāhaka Matua Hakarau Māhiohio – ITS Services</span><span style="font-size:12.0pt;mso-fareast-language:EN-NZ"><o:p></o:p></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><span style="mso-fareast-language:EN-NZ"><o:p> </o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>