Hi Phil,
Thanks for reaching out :)
At the top of our list is implementing shib groups. We need group definitions that are more targeted than "all users from institution X (i.e. identified by identity provider X)" and therefore need to check more than one attribute in SAML messages to determine
group membership. This is issue 1515 ("arbitrary attributes and regex support") and we want to contribute code for this issue, but I have to fight for the needed developer time. I foresee a change to the model of group definitions and possibly a change to
the API and have asked for feedback on this list.
Second on the list is 2548 ("Shibboleth/UI/config: one-click IdP-selection, DiscoFeed-bypass"). We use an external discovery service, so a dropdown list for IdPs could be replaced by a button or link. Also, the hardcoded link to the JSON feed for IdP names
should be configurable.
Regards,
Ben