<AttributeAcceptancePolicy xmlns="urn:mace:shibboleth:1.0">
	
	<!--
	An AAP is a set of AttributeRule elements, each one
	referencing a specific attribute by URI. All attributes that
	should be visible to an application running at the target should
	be listed, or they will be filtered out.
	
	Scoped attributes are also filtered on Scope via the Domain elements
	in the site metadata.
	-->
	
	<!-- Filtering rule to limit values to eduPerson-defined enumeration. -->
	<AttributeRule Name="urn:mace:dir:attribute-def:eduPersonScopedAffiliation"
			Header="Shib-EP-Affiliation" Alias="affiliation">
        <AnySite>
            <Value>member</Value>
            <Value>faculty</Value>
            <Value>student</Value>
            <Value>staff</Value>
            <Value>alum</Value>
            <Value>affiliate</Value>
            <Value>employee</Value>
        </AnySite>
	</AttributeRule>

	<!-- Basic rule to pass through any value. -->
    <AttributeRule Name="urn:mace:dir:attribute-def:eduPersonPrincipalName"
			Header="REMOTE_USER" Alias="user">
        <AnySite>
            <AnyValue/>
        </AnySite>
    </AttributeRule>

	<!-- Entitlements tend to be filtered per-site. -->
	<AttributeRule Name="urn:mace:dir:attribute-def:eduPersonEntitlement"
			Header="Shib-EP-Entitlement" Alias="entitlement">

		<!--
		Optional site rule that applies to any site
		<AnySite>
			<Value>urn:mace:example.edu:exampleEntitlement</Value>
		</AnySite>
		-->
		
		<!-- Specific rules for an origin site, these are just InQueue development/sample sites. -->
		<SiteRule Name="urn:mace:inqueue:example.edu">
			<Value Type="regexp">^urn:mace:.+$</Value>
		</SiteRule>
		<SiteRule Name="urn:mace:inqueue:shibdev.edu">
			<Value Type="regexp">^urn:mace:.+$</Value>
		</SiteRule>
	</AttributeRule>

</AttributeAcceptancePolicy>
