RE: [security-services] underspecified behavior for AuthenticationQuery ?
> Thanks, Prateek. The explanations make sense. I agree with > you that we should add this general rule to the appropriate sections. You might also want to define/specify a formal subcode underneath Success to indicate the "no assertions returned" condition. You wouldn't want applications looking at (even an optional) text message. -- Scott