#this is the reference to the current evaluation context in an OGNL expression. In PingFederate mappings, it points to the object that holds the attributes available for that step, allowing the expression to retrieve values such as assertion data, adapter attributes, or datasource lookups.
What #this Means in an OGNL Mapping
#this is the current evaluation context in OGNL, so it refers to the object being examined at that point in the expression. In PingFederate mappings, that context object is what exposes the attributes available to the step, which makes #this the anchor for retrieving values from assertion data, adapter attributes, or datasource lookups.
This matters because OGNL expressions are evaluated against whatever object is in scope, not against a global namespace. If the current context changes, #this changes with it, and the same expression can resolve to different data depending on the mapping step and the object model presented by PingFederate.
How #this Works in Expression Evaluation
OGNL uses #this as a context reference when an expression needs to operate on the current object rather than on a named variable or a root object. That makes it useful in projections, selections, and chained lookups where the expression must follow the active evaluation target through each step.
In practical terms, the attribute set you can access through #this is defined by the surrounding runtime context. In a PingFederate mapping, that may include attributes pulled from an assertion, adapter contract, or directory query, so the expression author needs to understand which object is actually in scope before assuming a value will resolve.
Why #this Matters for PingFederate Mappings
#this is important in PingFederate because mappings often translate between heterogeneous attribute sources. When the expression is written correctly, it can access the exact object handed to the step and retrieve the values needed to build an outgoing claim, transform a source attribute, or reference a lookup result.
That also means the term is tightly tied to evaluation context, not just syntax. A mapping that works in one adapter or assertion flow may fail in another if the current context object has different properties, nested structure, or null handling behavior.
Common Usage Patterns and Limits
#this is usually seen in expressions that iterate over a collection, filter objects, or dereference fields from the current item. The reference is concise, but it is only as accurate as the object model behind it, so developers still need to know whether the current item is a simple value, a structured attribute record, or a lookup result.
It is also easy to confuse #this with a stable variable name. It is not a named attribute repository, and it does not guarantee that every desired field exists, only that the expression engine is currently evaluating one object at a time within the step context.
Risk and Threat Considerations
Misunderstanding #this can produce incorrect attribute resolution, which in identity mappings can become a data integrity issue rather than a syntax issue. If an expression resolves against the wrong object or a null context, it may emit the wrong claim value, skip a required attribute, or expose incomplete data to the relying flow.
Failure mechanism: The expression author assumes the current object has a field that is not actually present in that step, or the context changes during iteration and the reference resolves to an unintended object.
Impact: Authentication or federation logic can receive incorrect attribute values, causing failed mappings, misleading downstream policy decisions, or unintended account and assertion behavior.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, OWASP ASVS and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Covers secure handling of identity-bearing values used in mapping flows. |
| AC-6 — Least Privilege | Supports limiting what mapping steps can access from the current context. | |
| AU-3 — Content of Audit Records | Helps record the attribute and context resolution used during mapping decisions. | |
| Recommendation — Manage mapping secrets and credentials with controlled issuance, rotation, and revocation. Restrict each mapping step to only the attributes it needs. Log enough mapping context to reconstruct how a value was resolved. | ||
| OWASP ASVS | V8 — Authorization | Addresses correct access to application data used in expression-driven mappings. |
| Recommendation — Validate that each expression can only access data permitted by its scope. | ||
| CIS Controls v8 | CIS-5 — Account Management | Relates to governing the identities and access paths that populate mapping context. |
| Recommendation — Review which accounts and data sources feed mapping inputs and retire stale ones. | ||
Practitioner Guidance
What to watch for: Use #this only when the expression is intentionally written around the active evaluation object, and verify the object shape at each mapping step. In practice, the safest mental model is “current context first, attribute access second,” because the reference is only meaningful if the surrounding step really supplies the value you expect.
Practitioner takeaway: If a PingFederate mapping behaves unexpectedly, inspect the evaluation context before changing the expression logic, because #this usually reveals a context mismatch, not a syntax problem.