Re: special characters in SAML attributes & shibuser.txt

"Barrett, Michael" <[email protected]> Thu, 12 Dec 2019 16:48:38 +0000
Newsgroups gmane.education.ezproxy
Message-ID <[email protected]>
My Shibboleth Attributes page also shows the friendly name and scope as empty for all attributes returned, but none of my attributes have signed parents  or such odd names.

Have you tried all possible escapes and quoting patterns?, i.e.

If auth:/UserAttribute[@yaddayadda:targetAttribute="yadduyaddu"] eq "TRUE"
If auth:’/UserAttribute[@yaddayadda:targetAttribute="yadduyaddu"]’ eq "TRUE"
If ‘auth:/UserAttribute[@yaddayadda:targetAttribute="yadduyaddu"]’ eq "TRUE"
If auth:”/UserAttribute[@yaddayadda:targetAttribute=\"yadduyaddu\"]” eq "TRUE"
If auth:/UserAttribute\[@yaddayadda:targetAttribute="yadduyaddu"\] eq "TRUE"
If auth:/UserAttribute[\@yaddayadda:targetAttribute="yadduyaddu"] eq "TRUE"

etc?

“When using auth:, the variable names can include any of these additional special characters: ! # $ % & * + - . / ^ | ~”
https://help.oclc.org/Library_Management/EZproxy/Authenticate_users/Directives_and_configurations_for_authentication/Expressions

I notice that ‘/’,’[‘,’@’,’:’,’=’,’”’and’]’, all the special characters in your attribute name, are not included among the allowable variable names, but I’m not sure it applies to attribute names.

In the same document I see

Any(aggvar, str)

This Boolean function returns 1 if any of the values of aggvar is case-sensitive equal to str, 0 if not.


and your attribute name/value pair kind of looks like a description of a hash named “UserAttribute” in which the index “{yaddayadda}{yadduyaddu}” has the value “TRUE” It’s a longshot but maybe
Any(UserAtribute,”TRUE”) would fire for this case, but then it might also fire for any other index in the hash that has the value “TRUE”.

If anyone out there has experience with either attribute names of this type, or “aggvar” attributes, feel free to correct my guesses

- Mike

Mike Barrett
Systems Administrator
Health Sciences Library
Pronouns: he, him, his

NYU Langone Health
NYU Grossman School of Medicine
577 First Avenue
New York, NY 10016

T 212-263-6691
[email protected]


From: EZproxy List <[email protected]> On Behalf Of Menna, G.
Sent: Thursday, December 12, 2019 10:01 AM
To: [email protected]
Subject: [EZPROXY-L] special characters in SAML attributes & shibuser.txt


[EXTERNAL]
OK guys, the first step is admitting I cannot fix it.

The shibboleth attributes that I am getting are, for example:
Row=1
Name= /UserAttribute[@yaddayadda:targetAttribute="yadduyaddu"]
Value=TRUE
Path= /samlp:Response/ saml:Assertion/ saml:AttributeStatement/ saml:Attribute[1]/ saml:AttributeValue 
Friendly Name = *empty*
Scope = *empty*

▣ Valid
▣ In Scope *
▢ Encrypted Parent
▣ Signed Parent
▢ HTTPS GET Method

All green on the ezproxy saml page.

So, the aim would be If auth:”/UserAttribute[@yaddayadda:targetAttribute="yadduyaddu"]” eq “true”; Deny deny.htm

And for the love of me I cannot manage to trigger them via shibuser.txt

I tried escaping the special characters with “\” but nope, no luck!

Any ideas? Open to anything!


Met vriendelijke groet / Kind regards,

Giulio Menna

Giulio Menna MA,
Developer / Application Manager

Monday, Tuesday, Wednesday, Thursday

T: 071-5272333
E: [email protected]<mailto:[email protected]>

Universitaire Bibliotheken, Leiden
Postbus 9501, 2300 RA Leiden
www.bibliotheek.leidenuniv.nl<https://urldefense.proofpoint.com/v2/url?u=https-3A__webmail.campus.leidenuniv.nl_owa_UrlBlockedError.aspx&d=DwMGaQ&c=j5oPpO0eBH1iio48DtsedeElZfc04rx3ExJHeIIZuCs&r=TQ1cn16cFHZD-CA1jRY37JndJXdw8-m4KLaYU4Xgddk&m=MRRhpZKPWsJ-Rk4PDVjYqXM0wFfItiQIoxF6xioKDOE&s=LXNMeRjR7QIld7QRAWIvad-jqU5ebiRhvGLnmEswz_I&e=>




________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://urldefense.proofpoint.com/v2/url?u=http-3A__listserv.oclclists.org_scripts_wa.exe-3FSUBED1-3DEZPROXY-2DL-26A-3D1&d=DwMGaQ&c=j5oPpO0eBH1iio48DtsedeElZfc04rx3ExJHeIIZuCs&r=TQ1cn16cFHZD-CA1jRY37JndJXdw8-m4KLaYU4Xgddk&m=MRRhpZKPWsJ-Rk4PDVjYqXM0wFfItiQIoxF6xioKDOE&s=dntEsTtlgxxy5XfCCiBfyacOIs0OOnUG6oNE3v5SOTA&e=>

********************************************************************
If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences,
you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>.
Or email [email protected] including the relevant text below in the body of the email:
• To unsubscribe: "unsubscribe EZPROXY-L"
• To receive EZPROXY-L in digest form: "set EZPROXY-L digest"
• To set your options to no mail: "set EZPROXY-L nomail"
• To receive these messages in the future "set EZPROXY-L mail"
To contact the list owners directly please send your message to [email protected].
If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum.
To unsubscribe from all OCLC marketing email communications
(including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters),
please email us at [email protected].