This repository was archived by the owner on Dec 13, 2018. It is now read-only.

Description
WsFed has historically not used anti-xsrf cookies because it supports unsolicited logins. However anti-xsrf cookies could be used if there was an opt-out option for applications that required support for unsolicited logins.
#1441 (comment)
@brentschmaltz how common is it for apps to rely on unsolicited logins?