> Login URL
> We check that:
>    - 
>    it is reachable,
>    - 
>    and returns a 200 HTTP status code.
I think that is potentially a bad idea.  Whilst currently the /login page 
returns a 200 it should only do this if you are not logged in and are using 
an AbstractPasswordBasedSecurityRealm based SecurityReakm.  For a non 
username password provider (google/SAML etc) IMO it should redirect to the 
actual login url AuthRealm  (link 

I consider the current behaviour of showing a username/password form a bug 
if you are either logged in or are not using something that can actually 
authenticate with a username and password. 



