REANNZ / federationregistry2-Tuakiri

Federation Registry2 by the Australian Access Federation - local Tuakiri customizations
http://www.aaf.edu.au
Apache License 2.0
4 stars 1 forks source link

Accept IdPs not known to FR (HostedIdP instances) in user authentication #9

Closed vladimir-mencl-eresearch closed 6 months ago

vladimir-mencl-eresearch commented 6 months ago

Allow users coming in from Hosted IdP instances to log into FR - more pressing now with members migrating to Hosted IdP.

Besides deploying this code change, will require also:

Already deployed in DEV (from a snapshot build) and working.

James-REANNZ commented 6 months ago

Looks good to me.

We may want to think about how to handle organisations that are associated with the Hosted IdP instance but aren't in the registry, but that might be handled by Federation Manager?

vladimir-mencl-eresearch commented 6 months ago

Thanks James!

The organisations for HostedIdP-only IdPS will have to be created manually in FR. They already exist for those migrated to HostedIdP from on-prem IdP (originally registered in FR) - and would have to be created manually for new deployments.

cangus commented 6 months ago

Great teamwork guys!

On 3 May 2024, at 2:40 PM, Vlad Mencl @.***> wrote:

Thanks James!

The organisations for HostedIdP-only IdPS will have to be created manually in FR. They already exist for those migrated to HostedIdP from on-prem IdP (originally registered in FR) - and would have to be created manually for new deployments.

— Reply to this email directly, view it on GitHub https://github.com/REANNZ/federationregistry2-Tuakiri/pull/9#issuecomment-2092038342, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAH57FCHFPZYEBMMLCAQLILZAL2IFAVCNFSM6AAAAABHEUIBY6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDAOJSGAZTQMZUGI. You are receiving this because you are subscribed to this thread.