<div dir="auto">You got me thinking of a related approach - update the metadata to send the 302 to a site I control where I could add the hint and use another 302 to forward it on - hacky but probably doable.</div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Mon, May 19, 2025, 12:32 PM Elle Weintraub <<a href="mailto:eweintra@jhmi.edu">eweintra@jhmi.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
Ahh...in that case maybe you can try switching from SP-initiated to IDP-initiated login, and have a landing or module that redirects it to the IDP-initiated logon URL with the login hint in place?</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
I'm not 100% sure if that would work, but that would be my next attempt.</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
<br>
</div>
<div id="m_-1519035359999226321Signature" style="color:inherit">
<p>-Elle Weintraub</p>
<p>Enterprise IT Architect</p>
<p>Enterprise Authentication Team Lead</p>
<p>Enterprise Authentication & Cloud Workspace</p>
<p>IT@Johns Hopkins</p>
<p>Johns Hopkins at Mt. Washington</p>
<p><a href="https://www.google.com/maps/search/5801+Smith+Ave?entry=gmail&source=g">5801 Smith Ave</a>.</p>
<p>Davis Building Suite 3110B</p>
<p>Baltimore, MD 21209</p>
<p>E-mail: <a href="mailto:eweintra@jhmi.edu" style="margin-top:0px;margin-bottom:0px" target="_blank" rel="noreferrer">
eweintra@jhmi.edu</a></p>
<p>Pronouns: She, Her, Hers</p>
<p> </p>
<p><img id="m_-1519035359999226321imageSelected0" width="230" height="55" style="width:230px;height:55px;margin-top:0px;margin-bottom:0px" src="cid:682c297e-e6ee-46aa-b07f-cbc7ed02a723"></p>
<p> <span style="color:rgb(0,0,0)"><a href="https://outlook.office.com/bookwithme/user/11769335e464489e904f6201df5ca964@jhmi.edu?anonymous&ep=pcard" style="margin-top:0px;margin-bottom:0px" target="_blank" rel="noreferrer">Book time with Elle Weintraub
</a></span></p>
</div>
<div id="m_-1519035359999226321appendonsend"></div>
<hr style="display:inline-block;width:98%">
<div id="m_-1519035359999226321divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> cneberg <<a href="mailto:cneberg@gmail.com" target="_blank" rel="noreferrer">cneberg@gmail.com</a>><br>
<b>Sent:</b> Monday, May 19, 2025 10:23 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank" rel="noreferrer">users@shibboleth.net</a>><br>
<b>Cc:</b> Elle Weintraub <<a href="mailto:eweintra@jhmi.edu" target="_blank" rel="noreferrer">eweintra@jhmi.edu</a>>; Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank" rel="noreferrer">cantor.2@osu.edu</a>><br>
<b>Subject:</b> Re: login_hint from shibboleth sp to azure idp</font>
<div> </div>
</div>
<div>
<p><strong><br>
</strong><strong><span style="background:red;color:white;font-family:"Times New Roman",serif;font-size:12pt"> External Email - Use Caution </span></strong></p>
<p><strong><span style="background:red;color:white;font-family:"Times New Roman",serif;font-size:12pt"><br>
</span></strong></p>
<p><strong><span style="background:red;color:white;font-family:"Times New Roman",serif;font-size:12pt"><br>
</span></strong></p>
<div>
<div dir="auto">
<div>Thank you Elle for the suggestion but I do need it per user - I was going to keep track of the last selected username in a persistent cookie.</div>
<div dir="auto"><br>
</div>
<div dir="auto"><br>
<div dir="auto">
<div dir="ltr">On Mon, May 19, 2025, 8:19 AM Cantor, Scott via users <<a href="mailto:users@shibboleth.net" rel="noreferrer noreferrer" target="_blank">users@shibboleth.net</a>> wrote:<br>
</div>
<blockquote style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
> You should be able to modify the Metadata for the Azure IdP to<br>
>add ?whr=<login-hint-domain> to the SingleSignOnService URLs,<br>
> as long as you are hosting a copy locally that you can edit.<br>
<br>
I assumed the goal was a per-user hint, but if it's static, yes, that should work. Our code is smart enough to detect the existing query string AFAIK.<br>
<br>
-- Scott<br>
<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">
https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" rel="noreferrer noreferrer noreferrer" target="_blank">
users-unsubscribe@shibboleth.net</a><br>
</blockquote>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote></div>