KantaraInitiative / SAMLprofiles

SAML interoperability and deployment profiles
Other
11 stars 4 forks source link

Non-normative text in section 4.1.4 includes a question aimed at us profile writers #44

Closed alexstuart closed 6 years ago

alexstuart commented 6 years ago

Text of section is

When consuming SAML Attributes with standardized definitions in external specifications, SPs MUST NOT impose constraints beyond the definitions of those attributes.

This may imply supporting extra long attribute values, attributes that contain multiple values, broad character set support, etc. Maybe this is less critical with the subject ID changes?

scantor commented 6 years ago

I think all those points are true, but are essentially the point here. If you consume, e.g. givenName, and tell somebody they have to send you one value, you are in error. That's what the language is trying to say. I will add that as an example, in fact.

ergood commented 6 years ago

For completeness, this was done in https://github.com/KantaraInitiative/SAMLprofiles/commit/47b359703aee17393261e9a9609499419a6d42fc