<div dir="ltr"><div>Good morning:</div><div><br></div><div>We're experiencing a pain point with the SP and I wanted to see if there is some advice on how to mitigate it.  We're using the Shibboleth SP with Apache as a transparent authenticating proxy in front of our app, and our app which allows data entry via HTTP POST requests.  We're seeing issues where the user submits data via a HTTP post, but their session with the SP has expired so the SP redirects to the IdP to re-authenticate.  When the reauthentication happens the POST data is lost.  We do have our session timeout values turned up but that is only reducing the probability of this error, not fully preventing against it.<br></div><div><br></div><div>My understanding is that this is a protocol level problem, and that it isn't possible to maintain the POST data through the redirect.  Is that correct?  Are there any quick wins to defend against this we can implement?  <br></div><div><br></div><div><div><div dir="ltr" class="m_-5740217460269663759gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><span style="font-size:12.8px">--Tom Noonan II</span><br></div></div></div></div></div></div></div></div>