login_hint from shibboleth sp to azure idp
Cantor, Scott
cantor.2 at osu.edu
Tue May 20 12:10:52 UTC 2025
> You got me thinking of a related approach - update the
> metadata to send the 302 to a site I control where I could add
> the hint and use another 302 to forward it on - hacky but
> probably doable.
Generally invalid because of the Destinatioon attribute, but technically that doesn't have to be checked if the request isn't signed. You'd run into implementations that would though.
-- Scott
More information about the users
mailing list