Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-5277

ConditionsProvider receives limited information from SAMLTokenRenewer

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.7.6
    • 2.6.10, 2.7.7
    • STS
    • None
    • Unknown

    Description

      The ConditionsProvider receives only the appliesToAddress and lifetime when called from SAMLTokenRenewer. This is in contrast to issue operations where the full TokenProviderParameters is passed. This makes it difficult to calculate conditions based on other attributes of the request. For example, a ConditionsProvider implementation may wish to restrict renewals to a limited time period based on the AuthnInstant attribute of an AuthnStatement in the assertion being renewed.

      If the full TokenRenewerParamters were passed instead then the necessary information would be available to perform more complex calculations.

      Attachments

        Activity

          People

            coheigea Colm O hEigeartaigh
            ethan.wallwork Ethan Wallwork
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: