Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Shibboleth Developer's Meeting, 2019-06-07

Call Administrivia

09:00 Central US / 10:00 Eastern US / 15:00 UK / 17:00 FI

Calls are normally the 1st and 3rd Fridays of each month. Next call would be Friday 2019-06-21. Any reason to deviate from this?

60 to 90 minute call window.


Call Details

This week's call will use the Zoom system at GU, see ZoomGU for access info.


AGENDA

  • Rod Widdowson 
    Jira Legacy
    serverShibboleth JIRA
    columnskey,summary,type,created,updated,due,assignee,reporter,priority,status,resolution
    serverId180d847f-bce4-36b2-9964-771bff586829
    keyIDP-1451
     Code refactoring.  Useful or rock-fetch?
  • Jira Legacy
    serverShibboleth JIRA
    columnskey,summary,type,created,updated,due,assignee,reporter,priority,status,resolution
    serverId180d847f-bce4-36b2-9964-771bff586829
    keyIDP-1464
     
  • Jira Legacy
    serverShibboleth JIRA
    serverId180d847f-bce4-36b2-9964-771bff586829
    keyIDP-1463
  • java-support – renaming artifact / dealing with implementation classes

Attendees:


Brent


Daniel


Henri

  • Progressing with RoleDescriptor for OIDC RPs (oidcmd:OAuthRPRoleDescriptorType)
    • Getting close to a successful PoC sequence with implicit flow (i.e. no client secrets needed yet)
  • GÉANT plugin team loses resources

Ian


Marvin


Phil

  • Working on PoC for anti-csrf token. Very early stage document of options CSRF Mitigation Options
    • Very much a WIP, so maybe only a light scan for those interested ATM. 
    • Basic implementation of Option 1 complete in local branch, will push to private repo next week. Will work a feature branch for all options (locally and private repo). 
      • Possible that none of the proposed options will be desirable! but at least it has got me thinking.


Rod

  • Eclipse is broken for me
    • Debugging of HashSets 
    • Finding all references of a class or method
  • Is this some compiler option we are not useing (debug/release builds?) or some eclipse setup I'm missing? Or is it just life in the 21st century?  Is there anything better?

...