Categories
Federated Services SSO Trust, Identity and Access Blogs UK Access Management Federation

There is a new WUGEN coming

Photo by Annie Spratt on Unsplash

WUGEN has been a well-loved tool for over a decade, helping librarians generate WAYFLess URLs that provide Single Sign On (SSO) authentication to the resources that students, staff and alumni need. Like all good things, however, technology developments have led to the WUGEN requiring a refresh, and so we are excited to announce its next generation.

Introducing WUGEN (Again…)

The latest generation of WUGEN has been built to succeed the legacy WUGEN application on the 15th September on the same URL (which can be found here), and carry its mission forward into its next decade of service. At its core, WUGEN performs the same functions as its predecessor, but with a modernised technology stack.

The process for generating WAYFLess URLs remains unchanged, and importantly, all previously generated URLs will continue to work as normal without interruption.

Fig 1. WUGEN’s generator page with typical inputs.

We’ve designed the user interface (UI) to feel familiar yet refreshed—bringing a modern feel and making it easier for both new and returning users to get started.

Plenty of contextual help is available: simply click on‌‍ the blue question mark‏ wherever it appears to reveal additional guidance. Accessibility has also been a core consideration, ensuring that all users can interact with WUGEN smoothly.

Our hope is that for those who have used WUGEN previously, the transition should feel natural, with no real learning curve.

Fig 2. An example of WAYFLess URLs generated by WUGEN.

Why do we need WUGEN?

WUGEN (short for URL Generator) helps address what is known as the Discovery Problem.

When a Service Provider (SP) wants to grant access to certain resources, it first needs to verify that the requester is authorised to view them. This is where an Identity Provider (IdP) comes in. A Service Provider delegates authentication to an IdPs so that students, staff & alumni can log in with their institution. The IdP acts as a trusted authority that confirms, “This person is who they say they are”, much like a passport.

So, can the SP rely on the IdP’s authentication to prove that a student should have access? Yes!

However, the Discovery Problem — a user experience (UX) problem — arises because there are many possible IdPs and the SP needs to know which one to use to perform the authentication. The student, staff member or alumni may have trouble correctly identifying who their IdP is, and even if they can, asking them to manually select it introduces unnecessary hoops for them to jump through. For a seamless user experience, this choice should ideally be made automatically, without requiring user input.

This is where WAYFLess URLs come in. A WAYFLess URL encodes information about which IdP the SP should use for authentication. With this information embedded, the authentication process can happen automatically and is invisible to the user. In other words, WAYFLess URLs overcome the challenges presented by the Discovery Problem.

Why is there a reliability scale in WUGEN?

WUGEN generates WAYFLess URLs using information from the UK Federation Metadata. As with any dataset, the quality and completeness of the data directly affect the quality of the URLs that can be produced.

To account for this, WUGEN uses five different generators to try to create as many WAYFless URLs for each IdP–SP pair as possible, depending on the data available. Some of these generators are considered more reliable — resistant to changes that might break links in the future — while others are more brittle.

The technical mechanics of these generators are outside the scope of this post. However, WUGEN (like its predecessor) includes a reliability scale and smart ordering to prioritise the most dependable options.

In addition, in more unique cases, Service Providers (SPs) can supply URL Templates that will generate WAYFLess URLs that are considered the most reliable option. If you operate an SP and would like to add a URL Template to WUGEN, please get in touch with us via service@ukfederation.org.uk, and we can help get you set up.

What next?

WUGEN was developed as a replacement for the legacy WUGEN. In its first release, our goal was to deliver a like-for-like replacement—retaining the same functionality but built on modern technology and presented in a refreshed, user-friendly interface. As always, we’re eager to learn how tools like WUGEN could be improved. If you have suggestions for new features or enhancements, we’d love to hear from you.

By Jonny Brownrigg

Jonny Brownrigg is a Software Engineer at Trust and Identity at Jisc.

Leave a Reply

Your email address will not be published. Required fields are marked *