> Then I thought we could expose information on the AuthenticationWorkflowDescriptor class API about what java.security.Principal information a workflow can produce, to support figuring out what workflows can be used. For example, by the former "information" do you mean annotations and the latter ... attributes ?