Hi Devs,<div><br></div><div>I&#39;ve noticed recently that an increasing number of SPs around my campus are requiring forceAuthn in an attempt to take back control of the user-auth/logout workflow.  The typical argument they make is &quot;think of the kiosk users&quot;.  Yeah Yeah, we&#39;ve all had these same arguments with vendors &amp; SP admins at our own institutions.   However, being an IdP admin and java developer who hates typing his password more than once per day, I&#39;d like to write some kind of extension or plugin which would instruct the IdP to ignore any forceAuthn requests for a particular list of users and just forge the response to make the SP think it got what it asked for.  </div>
<div><br></div><div>Before i proceed to just blindly hack this into the IdP, I was wondering if someone would give me a pointer of the best way to add this new feature in a pluggable &amp; maintainable way so I wouldn&#39;t need to keep a set of diffs around.</div>
<div><br></div><div>Thanks</div><div><br>Dave<br><br>-- <br>David Langenberg<div>Identity Management</div><div>The University of Chicago</div><br>
</div>