Only password authentication has been verified in the REST API.
[13:31:06] ‹mhwood› So, we're thinking that REST only does password authentication?
[13:31:54] ‹peterdietz› 5x only did password auth. During the refactor, I made a slight change:
[13:31:55] ‹peterdietz› authenticationService.authenticate(context, user.getEmail(), user.getPassword(), null, null);
[13:32:10] ‹peterdietz› Rely on the authenticationService stack to do what is appropriate
[13:32:24] ‹peterdietz› ...which might work for ldap
[13:32:27] ‹mhwood› That sounds better, thanks.
[13:33:16] ‹peterdietz› 5x did some ugly stuff, find person by email, and then check the password.. blurgh.. I need to review code better
[13:33:25] ‹terry-b› Any chance it would work with Shibboleth? Should I call login without a user id to test?
[13:34:28] ‹peterdietz› I'm not sure what the code will do in the case of an interactive login. It won't know where to redirect to