A user profile page deployed as part of Shibboleth IdP and SimpleSAMLphp would enable end users to gain insight into where their personal data is used and when it was last released to various services, as far as the IdP is aware. This feature should only release information to appropriate user (so after login). We need to consider how storing user data to facilitate this plugin would impact data retention policy of the IdP. We need to learn how both IdP products currently store information on what was release towards services and how that can be made readily available. Additional features to consider: - In case the IdP is also anOIDC OP this capability may be extended to also include OIDC based interactions.
- It should be investigated if this feature could also be used to allow users to retract consent to the release of attributes/claims
- Integration with CAR
|