Return-Path: X-Original-To: apmail-cxf-issues-archive@www.apache.org Delivered-To: apmail-cxf-issues-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id B62BD10B81 for ; Fri, 25 Jul 2014 19:50:41 +0000 (UTC) Received: (qmail 47838 invoked by uid 500); 25 Jul 2014 19:50:40 -0000 Delivered-To: apmail-cxf-issues-archive@cxf.apache.org Received: (qmail 47782 invoked by uid 500); 25 Jul 2014 19:50:40 -0000 Mailing-List: contact issues-help@cxf.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@cxf.apache.org Delivered-To: mailing list issues@cxf.apache.org Received: (qmail 47699 invoked by uid 99); 25 Jul 2014 19:50:40 -0000 Received: from arcas.apache.org (HELO arcas.apache.org) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 25 Jul 2014 19:50:40 +0000 Date: Fri, 25 Jul 2014 19:50:40 +0000 (UTC) From: "Jan Bernhardt (JIRA)" To: issues@cxf.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Closed] (CXF-5907) Full claim mapping enforcement in federated scenario MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 [ https://issues.apache.org/jira/browse/CXF-5907?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jan Bernhardt closed CXF-5907. ------------------------------ Resolution: Not a Problem Ups, sorry for the noise. This is not a bug. All works as it should be ;) > Full claim mapping enforcement in federated scenario > ---------------------------------------------------- > > Key: CXF-5907 > URL: https://issues.apache.org/jira/browse/CXF-5907 > Project: CXF > Issue Type: Bug > Components: STS > Affects Versions: 2.7.12, 3.0.1 > Reporter: Jan Bernhardt > Labels: claims, sts > > In case of federation claims can be mapped from one realm to another. Mapping can also include that some claim values are not relevant/desired for the target realm and thus should be omitted in the new token. However the {{org.apache.cxf.sts.claims.ClaimsManager}} enforces currently that all claim types contained in the request also must be included in the response by calling {{validateClaimValues(claims, targetClaims);}} at the end of the claim mapping. If some claim types have not been mapped to the new token, an exception is thrown. Therefore this check should be removed to allow mappings with different claim types in request and response. -- This message was sent by Atlassian JIRA (v6.2#6252)