#2 is not happening:
Login Step #2 "This plugin redirects the user to your IdP, along with a SAML Request that tells the IdP when the request was made, and where it should redirect the user back to if they log in successfully. It also “signs” the request so the IdP can be sure that the request is not being faked."