Attribute consent and revocation vs attibute queries

Description

As I've somewhere read that uApprove will be integrated to the IdP V3, and as (on V2 with uApprove) apparently the revocation of a consent doesn't have an effect on attibute queries, I propose a mechanism to have the user's persistent id deleted (or marked as unusable) on user's wish.

Environment

None

Activity

Takeshi NishimuraApril 17, 2019 at 9:34 AM

Thanks. It works as expected with both options.

Scott CantorMarch 4, 2019 at 2:45 PM

That and using a server-side storage option I suppose.

Takeshi NishimuraMarch 3, 2019 at 2:36 PM

I didn't find any documentation for this function.
Is it sufficient to turn shibboleth.consent.AttributeQuery.Condition to shibboleth.Conditions.TRUE ?

Tom ZellerSeptember 27, 2018 at 3:03 PM

182c2f8 Add to SAML 1

Tom ZellerSeptember 27, 2018 at 1:55 PM

 Need to add attribute-release-query subflow to SAML 1 attribute-query.

Fixed

Details

Assignee

Reporter

Components

Fix versions

Created August 7, 2014 at 3:06 PM
Updated April 17, 2019 at 9:34 AM
Resolved October 3, 2018 at 10:15 PM