<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks for the reply!</div>
<div class="elementToProof" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I finally figured this one out. For anyone that might run into the same problem, the issue is that when I used release attributes to ANY, the permission applies to both inbound (from the upstream idp) and the outbound (to the SP). So it worked and all attributes
 were able to resolve without issue.</div>
<div class="elementToProof" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
When I changed it to only release to certain SP, the attributes were not allowed in from the upstream idp, it then complained about attributes reseolved to null. Adding specific permission to allow the inbound attributes from the upstream idp makes it work
 again.</div>
<div class="elementToProof" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof ContentPasted0" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<AttributeFilterPolicy id="allow-inbound-idp"><br class="ContentPasted0">
        <PolicyRequirementRule xsi:type="Inbound" /><br>
</div>
<div class="elementToProof ContentPasted1" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span>    </span><AttributeRule attributeID="name" permitAny="true" /><br class="ContentPasted1">
</div>
<div class="elementToProof ContentPasted1" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span>    </span><AttributeRule attributeID="mail" permitAny="true" /></div>
<div class="elementToProof ContentPasted1 ContentPasted2" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
</AttributeFilterPolicyGroup></div>
<div class="elementToProof ContentPasted1 ContentPasted2" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof ContentPasted1 ContentPasted2 ContentPasted3" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<AttributeFilterPolicy id="saml-proxy-pass-through">
<div class="ContentPasted3">        <PolicyRequirementRule xsi:type="Requester" value="https://sp.example.com/sp" /></div>
<div class="ContentPasted3">        <span class="ContentPasted3"><AttributeRule attributeID="name" permitAny="true" /></span>
<br class="ContentPasted3">
</div>
<div class="ContentPasted3">        <AttributeRule attributeID="mail" permitAny="true" /></div>
<div></div>
 </AttributeFilterPolicy><br>
</div>
<div class="elementToProof ContentPasted1 ContentPasted2" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof ContentPasted4" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
This is all it needs to make it work to release the two attributes only to <a href="https://sp.example.com/sp" id="LPlnk821336">
https://sp.example.com/sp</a>.<br>
</div>
<div class="elementToProof" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks,</div>
<div class="elementToProof" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Johnny Z.<br>
</div>
<div class="elementToProof" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="appendonsend"></div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size: 11pt; color: rgb(0, 0, 0);" face="Calibri, sans-serif"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Rod Widdowson <rdw@steadingsoftware.com><br>
<b>Sent:</b> Sunday, April 23, 2023 4:36 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> [External] Re: attribute-filter.xml question</font>
<div> </div>
</div>
<div dir="auto">
<table style="border:0; display:table; width:100%; table-layout:fixed; border-collapse:seperate; float:none" width="100%" cellspacing="0" cellpadding="0" border="0" align="left">
<tbody style="display:block">
<tr>
<td cellpadding="7px 2px 7px 2px" style="padding: 7px 2px; background-color: rgb(166, 166, 166);" width="1px" valign="middle">
</td>
<td cellpadding="7px 5px 7px 15px" style="width: 100%; padding: 7px 5px 7px 15px; font-family: wf_segoe-ui_normal, Segoe UI, Segoe WP, Tahoma, Arial, sans-serif; font-size: 12px; font-weight: normal; text-align: left; overflow-wrap: break-word; color: rgb(33, 33, 33); background-color: rgb(234, 234, 234);" width="100%" valign="middle">
<div>You don't often get email from rdw@steadingsoftware.com. <a href="https://aka.ms/LearnAboutSenderIdentification" data-auth="NotApplicable">
Learn why this is important</a></div>
</td>
<td cellpadding="7px 5px 7px 5px" style="width: 75px; padding: 7px 5px; font-family: wf_segoe-ui_normal, Segoe UI, Segoe WP, Tahoma, Arial, sans-serif; font-size: 12px; font-weight: normal; text-align: left; overflow-wrap: break-word; color: rgb(33, 33, 33); background-color: rgb(234, 234, 234);" width="75px" valign="middle" align="left">
</td>
</tr>
</tbody>
</table>
<div><br>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: center; color: red;">
This message is from an EXTERNAL SENDER - be CAUTIOUS of links and attachments. THINK BEFORE YOU CLICK.</div>
<hr style="border-color:red">
<br>
<div><br>
<blockquote type="cite">
<div dir="ltr">
<div class="x_elementToProof x_ContentPasted0 x_ContentPasted1 x_ContentPasted3 x_ContentPasted4 x_ContentPasted5" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
The logs say name and mail resolved to null in this case. </div>
</div>
</blockquote>
<blockquote type="cite">
<div dir="ltr"><br>
</div>
</blockquote>
Attribute resolution happens long before attribute filtering.  So the configuration of the attribute filter can have no effect on that.  So either something else is changing or the logs are not telling you what they think are telling you.
<div><br>
</div>
<div>Both the attribute resolver and the attribute filter give pretty good logging information at debug.</div>
</div>
</div>
</div>
</body>
</html>