Mod-login SAML is not federation aware. No way to get automatic updates. No self registering.
How can configurations be preserved between instances (certficates change, backend urls change, metadata change)
Federation support is really needed.
Want to release SAML attributes for actions in FOLIO.
We need a gatekeeper for login. Something which says "this identifier is in the set of authorized logins"
A particular identity can be automatically authorized to login.
Qulto developed mod-login and mod-login-saml; they are not getting enough attention
These are real important modules
mod-SAML isn't actively maintained. Will be very important over the coming year and more. It definitely needs ownership, it's own service provider.
It would be an advantage to FOLIO to have active dev in this area.
Apache has modules for being a provider. NGINX has a 3rd party tool for this as well (it probably uses fast-cgi). Could FOLIO rely on these tools for SAML authentication and attribute release. Would eliminate the need to maintain the FOLIO SAML code.
FOLIO would need to be able to consume the data from both modules.
ToDo: Need several tickets for this in JIRA. Tod will create the ticket. These will be new requirements which will have deployment consequences.
There is a ticket for "federation support". "Login authentication atrribute" tickets are needed.
Need a PO for this. PO will write high level requirements and do priorization.
It will probably belong to "core platform" (but doesn't have to be)
Should also look at who owns the patron user loader.
This group will need to identify use cases. We take this on as a topic for this group.