<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
We do that as well. In particular edumember_is_member_of and eduperson_scoped_affiliation
<div class=""><br class="">
</div>
<div class="">Jim</div>
<div class=""><br class="">
<div><br class="">
<blockquote type="cite" class="">
<div class="">On Jun 8, 2020, at 12:59 PM, Liam Hoekenga <<a href="mailto:liamr@umich.edu" class="">liamr@umich.edu</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div dir="ltr" class="">Slightly off topic, but since I'm looking to define and release attributes using the Shib IDP, so slightly on topic?
<div class=""><br class="">
</div>
<div class="">For those of you who have deployed OIDC extension, what have you done for non-standard scopes and claims of useful data?</div>
<div class=""><br class="">
</div>
<div class="">Realistically, I think my team needs to sit down and maybe draft a umich scope (or scopes)? But in the meantime, I'm looking at attributes that are pretty common in SAML, but don't exist in one of the easily finable, defined standard OIDC scopes.</div>
<div class=""><br class="">
</div>
<div class="">I have been using a whitepaper from REFEDS to inform my actions.. <a href="https://wiki.refeds.org/download/attachments/38895621/20181011-OIDC-WP.pdf" class="">
White Paper for implementation of 4 mappings between SAML 2.0 and OpenID 5 Connect in Research and Education</a></div>
<div class=""><br class="">
</div>
<div class="">..specifically the stuff under section 8, "Advance profile":</div>
<div class=""><br class="">
</div>
<div class=""><i class="">Therefore, going from SAML to OIDC: </i></div>
<div class=""><i class="">● an underscore is used to separate words that would normally have a space in natural language;</i></div>
<div class=""><i class="">● the schema prefix of the attribute is retained, presented in lower case and separated by an underscore, and </i></div>
<div class=""><i class="">● camel case is converted into lower case, and again using underscores to separate words. </i><br class="">
</div>
<div class=""><i class=""><br class="">
</i></div>
<div class="">which leads to scope names like eduperson org inetorgperson, and claims named eduperson_principal_name or inetorgperson_employee_number</div>
<div class=""><br class="">
</div>
<div class="">I'm curious what other institutions are doing.</div>
<div class=""><br class="">
</div>
<div class="">thanks!</div>
<div class="">Liam</div>
</div>
-- <br class="">
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" class="">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br class="">
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">
users-unsubscribe@shibboleth.net</a><br class="">
</div>
</blockquote>
</div>
<br class="">
</div>
</body>
</html>