Users often make the mistakes such as: - Not having `strict-ssl` set to false - Not having `always-auth` set to true - Not _actually_ being logged in even with `always-auth` true