Shibboleth Developer's Meeting, 2019-07-19
Call Administrivia
09:00 Central US / 10:00 Eastern US / 15:00 UK / 17:00 FI
Calls are normally the 1st and 3rd Fridays of each month. Next call would be Friday 2019-08-02. Any reason to deviate from this?
60 to 90 minute call window.
This week's call will use the Zoom system at GU, see ZoomGU for access info.
AGENDA
Add items for discussion here
- (Phil) Around for the first 45 mins. Can discuss Anti-CSRF implementations if there is time (CSRF Mitigation Options)
- CI status / open issues
- SameSite status
Attendees:
Brent
- Out last nearly 2 weeks for conference and PTO.
Jira Legacy server Shibboleth JIRA columns key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution serverId 180d847f-bce4-36b2-9964-771bff586829 key IDP-1461 - Velocity 1.7 branch functionally complete; 2.1 just needs fixing up 1 more class.
- Still pending:
- a handful of missing unit tests
- SLF4J conversion
- style adjustments for Velocity conventions (tabs → spaces, etc).
- decision on whether to try to support Velocity 1.7 with another branch/artifact
Daniel
Henri
- On vacation, unable to attend the call today
- Updated the Wiki page regarding OIDC RP as EntityDescriptor: /wiki/spaces/DEV/pages/1177321591
- The plan is to use EntityDescriptor (client_id is entityID), UIInfo (for instance client_name is UIInfo/DisplayName) and custom role descriptor. The table of claim/XML-element relationships and the initial draft of the XML schema can be found from the page.
- The implementation still in progress: extended SAMLPeerEntityContext and SAMLMetadataContext are exploited by the actions.
...