New Feature Request
Summary
Problem: When communicating with SPs/RPs, the federation operator now cannot tell which attributes are available from the connected IdP's.
Value: This gives the federation operator insight in what attributes are available from which IdP, so attributes can be predicably released to SPs/RPs, according to the attribute release policy. This assumes attributes are filled with valid values, addressing that is a separate problem.
Proposed Solution
-
Action: For each authentication, log what IdP was used and which attributes (not values) were released by the IdP.
Possibly aggregate the data in EB itself.
-
Design: [Link to Figma/Screenshots]
-
Impact: Does this affect existing APIs or UI components?
Developer Checklist
To be completed by the developer during implementation.
Testing and QA
Describe how to verify and test this change.
Test Environment and Setup
- Point to [URL/Branch]
- Use account with [Role/Permissions]
Test Checklist
Extra Information
Add any other context, related issues, or technical notes here.
New Feature Request
Summary
Problem: When communicating with SPs/RPs, the federation operator now cannot tell which attributes are available from the connected IdP's.
Value: This gives the federation operator insight in what attributes are available from which IdP, so attributes can be predicably released to SPs/RPs, according to the attribute release policy. This assumes attributes are filled with valid values, addressing that is a separate problem.
Proposed Solution
Action: For each authentication, log what IdP was used and which attributes (not values) were released by the IdP.
Possibly aggregate the data in EB itself.
Design: [Link to Figma/Screenshots]
Impact: Does this affect existing APIs or UI components?
Developer Checklist
To be completed by the developer during implementation.
Testing and QA
Describe how to verify and test this change.
Test Environment and Setup
Test Checklist
Extra Information
Add any other context, related issues, or technical notes here.