Web Applications protected by the Sun Java System Access Manager Policy Agents version 2.2 can obtain the authenticated identity's attributes as well as the resource specific attributes by the following means
-
Set in as HTTP Header values
-
Set in the Browser Cookie as name value pairs.
In this part of doc, only the HTTP header option is discussed. The end application protected by the agents can obtain the authenticated identity's attributes as the HTTP header name value pairs in the following three ways:
-
Retrieve from authenticated identity's profile
-
Retrieve from authenticated identity's Session
-
Retrieve from policy resource response providers