<div dir="ltr">I suppose we were depending on it in the sense that we provided attr_2 to a small number of SPs who were unable to consume our multivalued attr_1 directly. We essentially synthesized attr_2 as a version of attr_1 that only provided a result for a specific potential value of attr_1. So it was sort-of-not-really the same thing for the less capable SPs. We distinguished them via their friendlyNames (and attribute IDs). Depending on whether the SPs in question were consuming the attributes by their Name or friendlyName, this may need to be accommodated if we change the underlying Name. Regardless, thanks for the explanation. Now that we know what the correct/expected behavior is going forward, we can work on fixing things on our end with more confidence.</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Jun 30, 2022 at 3:31 PM Cantor, Scott via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">You're probably talking about <a href="https://shibboleth.atlassian.net/browse/IDP-1936" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/browse/IDP-1936</a><br>
<br>
It is not a good idea in SAML to have two Attributes with the same name in an assertion, and while the Shibboleth SP handles that in a sane way, many won't (you might get the first one, the last, or both). I knew that it was doing that and I finally fixed it. It's always been broken, I think possibly as far back as the first versions, but I don't know for sure. It was just something you should never do, but I wanted it to do the right thing, finally, if somebody did it by accident.<br>
<br>
That should be the outcome you want if you're mapping two IdPAttributes to one SAML Attribute, otherwise you have little control over what the SP will do with it. If that's not what you want, you just shouldn't encode them to the same SAML Attribute.<br>
<br>
I don't see how you could have been "depending" on this before. A Shibboleth SP would have just combined them on the other end anyway, so it's not a change, and most other SPs wouldn't do anything predictable at all and you'd never want to depend on whatever they were doing.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><font face="arial, sans-serif">Baron Fujimoto <<a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> ::: UH Information Technology Services<br>minutas cantorum, minutas balorum, minutas carboratum descendus pantorum</font></div></div>