<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Feb 7, 2017 at 3:47 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div id="m_7467433264765486757:du1" class="m_7467433264765486757a3s m_7467433264765486757aXjCH m_7467433264765486757m15a1a8bea7d95c22">I have no idea if it's even sensible to try and combine RemoteUser methods, I can't see how that could work without using separate headers for the username.</div></blockquote><div><br></div><div>I've got an attribute that our SSO sets that says what authentication factors have been satisfied.</div><div>I could conditionally set headers based on what's there.</div><div><br></div><div>I could try collapsing the token and "plus" flows into the existing RemoteUser flow.<br></div><div><br></div><div>What would you suggest?</div><div><br></div><div>Liam</div><div><br></div><div><br></div></div></div></div>