I'm working on a system that will need to evaluate user's profile and
decided if the user can access a protected resource. If not, the user
need to be redirected to another page (a Servlet), in that Servlet, we
need the user's login ID to do some further check and show a customized
message. I could not find a way to pass the user's ID from authorization
policy (we used the extension SDK to make a customized policy). Any clue
and help?

