<html>
  <head>
    <meta content="text/html; charset=utf-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Il 14/12/2016 14:18,
      <a class="moz-txt-link-abbreviated" href="mailto:users-request@shibboleth.net">users-request@shibboleth.net</a> ha scritto:<br>
    </div>
    <blockquote
      cite="mid:mailman.4848.1481721504.4125.users@shibboleth.net"
      type="cite">
      <pre wrap=""><div class="moz-txt-sig">On 12/14/16, 4:29 AM, "users on behalf of Marco Naimoli" <a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="mailto:users-bounces@shibboleth.netonbehalfofmarco.naimoli@unipd.it"><users-bounces@shibboleth.net on behalf of marco.naimoli@unipd.it></a> wrote:

</div></pre>
      <blockquote type="cite" style="color: #000000;">
        <pre wrap=""><span class="moz-txt-citetags">> </span>What is the correct and simpler way to disable this feature (hope it's not creating a new flow) ?
</pre>
      </blockquote>
      <pre wrap="">There is no supported way. You can file a RFE for that, it would just take a fairly simple patch and you would be able to apply that ahead of time in a manner that would survive upgrades in the future since it would match the change made to the code.

I'd be curious why you care about this though.

-- Scott</pre>
    </blockquote>
    <p>I'd like to control to switch on or off this feature; I have this
      need because we have a test IDP installation, protected by a basic
      auth: users that wants</p>
    <p>to use it must authenticate with a personal password. Then they
      can do their tests using test users with test passwords; in a
      standard IDP installation <br>
    </p>
    <p>users receive an error about a failed authentication, due to the
      check of the basic auth data. It's an aesthetic problem, I could
      solve it modifying views,</p>
    <p>probably, but I don't want also that anyone can authenticate
      "outside" the IDP, to avoid that a site/webapp can be used to
      collect user passwords</p>
    <p>In the future I could choose to enable this feature, for some
      directly controlled SP: that's why I was looking a simple way
      (like changing a parameter)</p>
    <p>to switch the feature on or off<br>
    </p>
    <p>Thank you very much</p>
    <p>Marco<br>
    </p>
  </body>
</html>