<div dir="ltr"><div class="gmail_quote"><div dir="ltr">On Thu, Jun 28, 2018 at 11:44 AM Marvin Addison <<a href="mailto:marvin.addison@gmail.com" target="_blank">marvin.addison@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div class="gmail_quote"><div dir="ltr">On Mon, Jun 18, 2018 at 5:51 PM Greg Haverkamp <<a href="mailto:gahaverkamp@lbl.gov" target="_blank">gahaverkamp@lbl.gov</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">I haven't decided if it's better or worse, but I've lately started using activation conditions for these requests.<br></blockquote></div></blockquote><div><br></div><div>We've tried many solutions and I'm comfortable saying that activation conditions are the way to go for one-off attribute names. We're seeing an uptick in the number of integrations that require specific (and in many cases non-standard) attribute names, and activation conditions allow us to focus on these quirks by adding additional attribute encoders that are toggled with an activation condition as your example demonstrates. If you're doing consent or other flows that work on attribute sets, you'll appreciate the benefit of this approach even more.</div></div></div></blockquote><div><br></div><div>Well, I'll have to admit much of the reason that I questioned the value of them is because I apparently can't read.  I viewed the conditions as a "service", and I've been operating under the impression that any time I added a new predicate, I had to restart the IdP, because there was no reloadable service.  But just now, I re-read the ReloadableServices page, and realized that those beans get loaded by the services themselves, and so now I feel stupid.  (With local sessions, I can gracefully restart the IdP, but it takes a while, as I wait for the load balancer's sticky sessions to eventually drain everyone who's mid-login to switch.  And so I made the last user of an integrated application wait 2 or 3 days for me to restart...)</div><div> </div><div>So, the only reason I saw a completely new attribute as a potentially better approach was because I could reload the service. </div><div><br></div><div>Greg</div><div><br></div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div class="gmail_quote"><div><br></div><div>Marvin at Virginia Tech</div><div><br></div></div></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div></div>