You'd have to hack up the filter a bit, but wouldn't be terribly
difficult; in the catch block in NtlmHttpFilter (catching the
SmbAuthException) you would just skip the bit where it sets the
WWW-Authenticate header and sends back an SC_UNAUTHORIZED response.
Basically have it fall through the catch, setting some flag in the
session indicating anonymous logon.

> How can I do the following in a web app?
> If I can silently authenticate a user - do it
> If I can't, allow anonymous access
> The silent authentication is working great, but we do have some users who
> are not on our domain, so I want them to be able to use the app without
> being prompted for a user/pass which will just confuse them.
> Thanks for the help.
