From: Krzysztof B. <kb...@un...> - 2023-07-06 10:00:54
|
Hi Sander, W dniu 6.07.2023 o 10:42, Sander Apweiler pisze: > Hi Krzysztof, hi Roman, > we see a growing number of requests to the ORCID ID of researchers and > services who want this information from the IdM system. The primary > identity of the users is bound to the home organisation. Since there > are resources bound to this identities, we do not want to perform > account linking, unless we can remove all privileges, based on the > organisation login, of the users, if the user left the organisation. > ORCID login is an alternativ for researchers where the home > organisation does not release all mandatory attributes. > > Is it possible to get the ID directly from ORCID and storing this as > attribute, without account/identity linking? I'm not sure if I understand the scenario. Can you describe the flow precisely? I wonder how and when Unity instance shall authorize to ORCID to get this identity info? I understand that you have a user that has some home IdP + ORCID id. This user can login via Unity acting as a proxy to home IdP. And now how ORCID fits here? Best, Krzysztof |