This optional parameter specifies a list of attribute names
                  that are permitted in forwarded requests. Attributes whose names do not
                  appear in this list are stripped from the request before
                  forwarding.
               # Strip everything except username and password
AllowInRequest User-Name,User-Password