summaryrefslogtreecommitdiffstats
path: root/docs/reference/tmpl/lib_authn_request.sgml
diff options
context:
space:
mode:
Diffstat (limited to 'docs/reference/tmpl/lib_authn_request.sgml')
-rw-r--r--docs/reference/tmpl/lib_authn_request.sgml24
1 files changed, 23 insertions, 1 deletions
diff --git a/docs/reference/tmpl/lib_authn_request.sgml b/docs/reference/tmpl/lib_authn_request.sgml
index cb5d803e..827d988a 100644
--- a/docs/reference/tmpl/lib_authn_request.sgml
+++ b/docs/reference/tmpl/lib_authn_request.sgml
@@ -23,11 +23,33 @@ profile.</para></listitem>
<!-- ##### STRUCT LassoLibAuthnRequest ##### -->
<para>
-@nameIDPolicy must be one of #LASSO_LIB_NAMEID_POLICY_TYPE_NONE,
+@ProviderID is the service provider identifier, this field will often be filled
+with lasso_login_init_authn_request().
+</para>
+
+<para>
+@nameIDPolicy tells the identity provider about the policy to use for
+federation; it must be one of #LASSO_LIB_NAMEID_POLICY_TYPE_NONE,
#LASSO_LIB_NAMEID_POLICY_TYPE_ONE_TIME, #LASSO_LIB_NAMEID_POLICY_TYPE_FEDERATED
or #LASSO_LIB_NAMEID_POLICY_TYPE_ANY.
</para>
+<para>
+@IsPassive; if %TRUE (default) it tells the identity provider not to interact
+with the user.
+</para>
+
+<para>
+@ForceAuthn; only used if @IsPassive is %FALSE, it tells the identity provider
+to force authentication of the user even when already authenticated.
+</para>
+
+<para>
+@ProtocolProfile is the Single Sign-On and Federation profile to adopt; either
+#LASSO_LIB_PROTOCOL_PROFILE_BRWS_ART (which is the default value) or
+#LASSO_LIB_PROTOCOL_PROFILE_BRWS_POST.
+</para>
+
@Extension:
@ProviderID:
@AffiliationID: