Adding forced password reset?

>Having the change password page behind SSO can leave a hole open to the
>forced password change. User logs in, gets Shib session, directed to
>change password. Simply ignores it and accesses their original target.
>Previous session handler sends them to the original target. Just be aware
>it's a circumstance you have to allow for.

Yeah, "force" is something only the authentication system can impose, but
reminding is what we do. My custom handler contribution includes a
submodule that detects password age based on a resolved attribute and
drops a cookie to track reminders every so many hours.

