On 31 May 2011, at 12:37, Colleen Romero wrote:
> saml:AttributeScopeMatchesShibMDScope
This checks that
a) The scope you're asserting matches the one registered in the metadata for your IdP (to stop you asserting someone else's scope); and
b) That no @ symbols exist in the value (things get confused if you send foo@bar@scope) !
R.
--
----------------------------------------------------------------------
Dr Rhys Smith e: [log in to unmask]
Engineering Consultant: Identity & Access Management (GPG:0xDE2F024C)
Information Services,
Cardiff University, t: +44 (0) 29 2087 0126
39-41 Park Place, Cardiff, f: +44 (0) 29 2087 4285
CF10 3BB, United Kingdom. m: +44 (0) 7968 087 821
----------------------------------------------------------------------
|