> Yes, whitelisting, but ideally with a different whitelist based on the SP's > entityID and the endpoints in metadata, ideally. Not really that much work on top of doing one at all I suppose. -- Scott