<div dir="ltr">Ok, I think I may be using the wrong terminology. <br><br>Is it wrong of me to expect the ExpiringPasswordIntercept to function, even if we are using LDAP authentication? I would have thought that the authentication method would be independent. <div><br></div><div>Jeff</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Jun 28, 2023 at 2:40 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> Is there some way to get the ldap login flow to use the passwordExpiring IDP<br>
> Attribute? Or preferably to get the ExpiringPasswordIntercept to work with<br>
> Password auth?<br>
<br>
Login flows do not have any relationship to interceptors in that sense. The interceptors that run are based on the postAuthenticationFlows profile setting, which is something controlled based on relying party configuration and/or metadata, and has no connection back to how authentication is done in most cases. (*)<br>
<br>
-- Scott<br>
<br>
(*) An exotic Predicate could be coded up to examine authentication state to decide how to respond but that’s after the interceptor is running, not part of deciding whether to run.<br>
<br>
</blockquote></div><br clear="all"><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><pre cols="72">Jeff Chapin,</pre>Panther eSports Adviser            <br>Systems/Applications Administrator<br>ITS-IS, University of Northern Iowa<br>Phone: 319-273-3162 Email: <a href="mailto:Jeff.Chapin@uni.edu" target="_blank">Jeff.Chapin@uni.edu</a> </div></div></div></div>