At the moment, the IDPAuthnContextMapper has access to the incoming SAML2 AuthnReqest:
However, in the case of IDP-Initiated SSO, there is no SAML2 AuthnRequest, as a result, IDP is unaware of the SP involved. The request is to extend the IDPAuthnContextMapper interface and provide access to the HTTP request object, specifically to the #getIDPAuthnContextInfo method.
The HTTP request object will include the spEntityID as a query parameter and IDP can make decisions per-SP.
This will be needed for OPENAM-16541.