> generated key contains only the SP's entityID and this causes consent > decisions to ignore the user being authenticated (e.g. the first user to > ever log in on the IdP gets the ToU prompt then nobody else gets it, for > a given SP). I assume you are using server-side storage for consent, correct ?