<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">That was at least one of the options I was considering so if you wanted to commit that, I'm ok with it. I don't think I filed an issue for this yet.<br></blockquote><div><br></div><div>I did some further testing and it turns out this is not sufficient for our use case. In short, the flow filtering mechanism that is enabled by the patch is too strict when applied to the initial authn case. I can imagine further knobs to make it work, but it feels like the wrong approach in light of simply developing a custom flow. I think it's fair to say that our use case is at present fairly uncommon and it's not worthwhile to accommodate in a general way. I intend to document my work and the obstacles in further detail on the shib-assurance wiki so that they're captured for posterity. Maybe similar use cases will arise in the future and we'll have enough data to develop a general solution.</div><div><br></div><div>Best,</div><div>M<a href="mailto:dev-unsubscribe@shibboleth.net" target="_blank"></a><br>
</div><div><br></div></div></div>