Hi Gilles,
I don't think you can really have the SPA (client-side code) act as an "authentication application". The client is effectively untrusted so you can't have it asserting identity into your security system.
I assume that the SPA will be calling REST services at some backend application to validate gathered authentication data. This (trusted) backend service - sitting on an ISAM junction - will need to respond with the EAI headers to complete the authentication.
@Philip Nye can comment but I suspect that his note was really saying that the EAI headers should be added to the final REST *response* in the authentication flow. That same REST API URL should be configured as the trigger URL.
Jon.
P.S. I think your signature is out of date. I don't think you're in Fareham any more ;-)
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------