IdP-initiated SSO

Netix SP sets allow_unsolicited=False, so this path is expected to fail against Netix — useful as a negative test.