I see what you're saying about exposing the password to the sp site, (which was the old idp essentially), but I feel like an ajax call could talk to the idp service and set the cookie.
Anyway, perhaps a better solution would be this. How do I style the idp login in gluu, such that it is not glaringly obviously not apart of the existing site?