Cantor, Scott via users <users at shibboleth.net> [2024-03-11 17:53 CET]: > though I'm no fan of "hack in a header for security", that's nothing > more than reinventing basic-auth, kind of silly. If one asked the vendor I'm sure they're convinced they actually *are* using HTTP Basic Auth here. -peter