This is exactly what is supposed to happen.
You authenticate at the IdP, which is a different site.
If it's not, then Peter's comments apply and you could just use local
logins and don't use SimpleSAMLphp at all.
What you're trying to do in the above code (capturing
username/password and using these to log in) is called phishing.
--
Dick Visser
Sr. System & Networking Engineer
GÉANT Association, Amsterdam Office (formerly TERENA)
Singel 468D, 1017 AW Amsterdam, the Netherlands
Tel:
+31 (0) 20 530 4488
GÉANT Association
Networking. Services. People.
Learn more at:
http://www.geant.org