the way I have implemented this currently is: the page generates a random ID, javascript sends that to my custom browserplugin. browser plugin executes a python script which writes ~/.loginid, osquery is watching ~/.loginid for all users and sends an update to the TLS controller, then the page checks in with the TLS controller until it sees a matching ID