Namespace: urn:mace:shibboleth:2.0:afp
Schema: http://shibboleth.net/schema/idp/shibboleth-afp.xsd
Overview
The IssuerRegex
is a PolicyRule which returns true if the entityID of the party issuing the attributes (usually, but not always, the IdP itself) matches the supplied Java regular expression.
The primary use case for this is proxying when filtering inbound attributes, or in "multi-homing" scenarios in which the IdP may be representing multiple sources of attributes itself under different names.
Reference
Attributes
Name | Type | Required? | Description |
---|---|---|---|
| Pattern | Y | Specifies the java regular expression to match against. |
Child Elements
None
Example
Apply this rule if the IdP entityID starts with "https://idp.example.org/":
<PolicyRequirementRule xsi:type="IssuerRegex" regex="^https://idp\.example\.org/.*$" />