OpenConext / OpenConext-attribute-aggregation

OpenConext attribute aggregation
Apache License 2.0
1 stars 2 forks source link

New AA to deliver manage content as an attribute #125

Closed phavekes closed 1 month ago

phavekes commented 1 month ago

This issue is imported from pivotal - Originaly created at Oct 28, 2019 by Thijs Kinkhorst

We want to provide the CRM GUID of a SURF customer to SURF\'s own SP\'s.

This value is always available in Manage for an IdP in the coin:institution_guid field. Its value is a (MS) format GUID.

Create an aggregator that produces the attribute urn:mace:surf.nl:attribute-def:surf-crm-id with the value that the user\'s IdP has in Manage. If there\'s no value, provide no attribute.

The value does not change often/at all, so some amount of caching is not a problem.

phavekes commented 1 month ago
@thijskh Is there an urn:oid alias for the new attribute? (Okke Harsta - Oct 28, 2019)
phavekes commented 1 month ago

1.3.6.1.4.1.1076.20.100.10.50.2 (Thijs Kinkhorst - Oct 28, 2019)

phavekes commented 1 month ago

1.3.6.1.4.1.1076.20.100.10.50.2 (Thijs Kinkhorst - Oct 28, 2019)

phavekes commented 1 month ago

Implemented and deployed: https://aa.test2.surfconext.nl/playground# (Okke Harsta - Oct 28, 2019)

phavekes commented 1 month ago

Works on the playground, but EB does not provide the IDPentityID attribute. Pull request https://github.com/OpenConext/OpenConext-engineblock/pull/799 is added as blocker (Okke Harsta - Oct 28, 2019)

phavekes commented 1 month ago

Looks good! FInal test to be done when EB supports this (Thijs Kinkhorst - Oct 29, 2019)