2024-05-17

Shibboleth Developer's Meeting, 2024-05-17

Call Administrivia

09:00 Central US / 10:00 Eastern US / 15:00 UK / 17:00 FI

Calls are normally the 1st and 3rd Fridays of each month. Next call would be Friday 2024-06-07. Any reason to deviate from this?

60 to 90 minute call window.

Call Details

This week's call will use the Zoom system at GU, see ZoomGU for access info.

AGENDA

Add items for discussion here

Attendees:

Brent

  • Nothing.

Daniel

 

Henri

Ian

  • May need to miss meeting, I have some people coming to fix our drains…

  • MDA 0.10.0 released. Huzzah!

    • Some downstream work to be done before I’m really finished.

    • main is now 1.0.0-SNAPSHOT and there’s a maint-0.10 branch.

    • I don’t see value at present in nightly and multi jobs on the maintenance branch, but will create them if needed.

  • New Spring Framework releases (including a new 6.2 milestone) available, will integrate those.

  • Next up after that: Git conversion of the Santuario repository

John

 

Marvin

 

Phil

  • https://shibboleth.atlassian.net/browse/JWEBAUTHN-12

    • Add a guard to check a user who has already registered a webauthn credential can not bypass webauthn authentication when registering a new one (under certain MFA configurations that allow some kind of alternate authentication to be used to bootstrap credentials).

      • In other flows, this is covered by requesting the correct authentication method/class principal etc

      • Is hard to think of all the options for trying to bootstrap the initial key, but I’ve tried to improve the documentation around this.

  • https://shibboleth.atlassian.net/browse/JWEBAUTHN-11

    • Pull user.id, user.name, and user.displayName from the attribute context for use when registering a new credential

  • https://shibboleth.atlassian.net/browse/JWEBAUTHN-8

    • Added an admin flow for admins to manage other users credentials. Only supports searching and removal for now.

  • Finishing the docs

  • 3rd Alpha was released. Will get a beta out before the end of the month. Hopefully not long after that for a v1.

  • Will produce a few videos so it is easy for others to review

 

Rod

  • Nothing

Scott

Tom

  • revising IdP integration tests after all the releases

  • IdP integration tests for Jetty 12

  • next up : Jenkins pipleline job to trigger integration tests

Other

Â