Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How does authoritativeGroups work on first use and first RP login? #210

Open
gene1wood opened this issue Aug 3, 2018 · 0 comments
Open

Comments

@gene1wood
Copy link
Contributor

gene1wood commented Aug 3, 2018

  1. How will a user have a authoritativeGroups list added to their user.app_metadata object? It looks like in the absence of the list no check is done but I don't see how the list is created and added to the user's user.app_metadata in the first place.
  2. Assuming the authoritativeGroups list exists in the user's user.app_metadata object, how are new RP objects added to the list? It looks like lastUsed values are updated if the RP already exists in authoritativeGroups but I don't see how, when a user first logs into an RP which has a expire_access_when_unused_after value, what creates a new object for that RP in the user's authoritativeGroups list.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant