No. I meant this paragraph: "The principal resolution machinery provided by AuthenticationHandler components should be used in preference to PrincipalResolver in any situation where the former provides adequate functionality. If the principal that is resolved by the authentication handler suffices, then a null value may be passed in place of the resolver bean id"
> -----Original Message----- > From: YunQiang Su [mailto:[email protected]] > Sent: Tuesday, January 12, 2016 5:56 AM > To: Misagh Moayyed <[email protected]> > Cc: CAS Community <[email protected]> > Subject: Re: [cas-user] Cas 4.2 RC1 attributes get problem > > On Tue, Jan 12, 2016 at 8:26 PM, Misagh Moayyed <[email protected]> > wrote: > > Study > > https://jasig.github.io/cas/4.2.x/installation/Configuring-Principal-R > > esolution.html > > I see it, while still some confused. > > Did you mean this one? > > https://wiki.jasig.org/display/PDM15/LDAP+Attribute+Source > > and get > > Caused by: > org.springframework.beans.factory.NoSuchBeanDefinitionException: > No qualifying bean of type > [org.jasig.services.persondir.IPersonAttributeDao] found for > dependency: expected at least 1 bean which qualifies as autowire candidate > for > this dependency. Dependency annotations: > {@org.springframework.beans.factory.annotation.Qualifier(value=attributeRep > ository)} > > > > > > > > > From: [email protected] [mailto:[email protected]] On Behalf Of > > Yunqiang Su > > Sent: Tuesday, January 12, 2016 12:34 AM > > To: CAS Community <[email protected]> > > Subject: [cas-user] Cas 4.2 RC1 attributes get problem > > > > > > > > I download and built cas 4.2 rc1, and modify some files. > > It can be used to authorize while I cannot get other attribute. > > > > As catalina.out said, > > ldapAuthenticationHandler can get these attributes, while on phpCAS, I > > get something like this: > > > > > > array(6) { > > ["accountStatus"]=> > > string(13) "accountStatus" > > ["name"]=> > > string(4) "name" > > ["authenticationDate"]=> > > string(29) "2016-01-12T14:23:02.032+08:00" > > ["isFromNewLogin"]=> > > string(4) "true" > > ["longTermAuthenticationRequestTokenUsed"]=> > > string(5) "false" > > ["unitId"]=> > > string(6) "unitId" > > } > > > > > > I think that the problem is caused by mis-configuration: > > attributeRepository. > > Any idea how to configure it? > > > > deployerConfigContext.xml > > > > <beans xmlns="http://www.springframework.org/schema/beans" > > xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" > > xmlns:ldaptive="http://www.ldaptive.org/schema/spring-ext" > > xmlns:context="http://www.springframework.org/schema/context" > > xmlns:p="http://www.springframework.org/schema/p" > > xmlns:c="http://www.springframework.org/schema/c" > > xmlns:aop="http://www.springframework.org/schema/aop" > > xmlns:tx="http://www.springframework.org/schema/tx" > > xmlns:util="http://www.springframework.org/schema/util" > > xmlns:sec="http://www.springframework.org/schema/security" > > xsi:schemaLocation="http://www.springframework.org/schema/beans > > http://www.springframework.org/schema/beans/spring-beans.xsd > > http://www.springframework.org/schema/tx > > http://www.springframework.org/schema/tx/spring-tx.xsd > > http://www.springframework.org/schema/aop > > http://www.springframework.org/schema/aop/spring-aop.xsd > > http://www.springframework.org/schema/context > > http://www.springframework.org/schema/context/spring-context.xsd > > http://www.springframework.org/schema/security > > http://www.springframework.org/schema/security/spring-security.xsd > > http://www.ldaptive.org/schema/spring-ext > > http://www.ldaptive.org/schema/spring-ext.xsd > > http://www.springframework.org/schema/util > > http://www.springframework.org/schema/util/spring-util.xsd"> > > > > <!-- auth with > > http://jasig.github.io/cas/development/installation/LDAP-Authentication.html > > LDAP Requiring Authenticated Search > > --> > > <bean id="ldapAuthenticationHandler" > > class="org.jasig.cas.authentication.LdapAuthenticationHandler" > > p:principalIdAttribute="uid" > > c:authenticator-ref="authenticator"> > > <property name="principalAttributeMap"> > > <map> > > <entry key="name" value="name" /> > > <entry key="accountStatus" value="accountStatus" /> > > <entry key="unitId" value="unitId" /> > > </map> > > </property> > > </bean> > > > > <ldaptive:bind-search-authenticator id="authenticator" > > ldapUrl="${ldap.url}" > > baseDn="${ldap.baseDn}" > > userFilter="${ldap.searchFilter}" > > bindDn="${ldap.managerDn}" > > bindCredential="${ldap.managerPassword}" > > connectTimeout="${ldap.connectTimeout}" > > useStartTLS="${ldap.useStartTLS}" > > blockWaitTime="${ldap.pool.blockWaitTime}" > > maxPoolSize="${ldap.pool.maxSize}" > > allowMultipleDns="${ldap.allowMultipleDns:false}" > > usePasswordPolicy="${ldap.usePpolicy:false}" > > minPoolSize="${ldap.pool.minSize}" > > validateOnCheckOut="${ldap.pool.validateOnCheckout}" > > validatePeriodically="${ldap.pool.validatePeriodically}" > > validatePeriod="${ldap.pool.validatePeriod}" > > idleTime="${ldap.pool.idleTime}" > > prunePeriod="${ldap.pool.prunePeriod}" > > failFastInitialize="true" > > subtreeSearch="${ldap.subtree.search:true}" > > useSSL="${ldap.use.ssl:false}" > > /> > > > > <util:map id="authenticationHandlersResolvers"> > > <entry key-ref="proxyAuthenticationHandler" > > value-ref="proxyPrincipalResolver" /> > > <entry key-ref="primaryAuthenticationHandler" > > value-ref="primaryPrincipalResolver" /> > > </util:map> > > <util:list id="authenticationMetadataPopulators" /> > > > > <!-- for attributions --> > > <bean id="attributeRepository" > > class="org.jasig.services.persondir.support.NamedStubPersonAttributeDao" > > p:backingMap-ref="attrRepoBackingMap" /> > > <util:map id="attrRepoBackingMap"> > > <entry key="name" value="name" /> > > <entry key="unitId" value="unitId" /> > > <entry key="accountStatus" value="accountStatus" /> > > </util:map> > > > > <alias name="ldapAuthenticationHandler" > > alias="primaryAuthenticationHandler" /> > > <alias name="personDirectoryPrincipalResolver" > > alias="primaryPrincipalResolver" /> > > > > <alias name="serviceThemeResolver" alias="themeResolver" /> > > > > <alias name="jsonServiceRegistryDao" alias="serviceRegistryDao" /> > > > > <alias name="defaultTicketRegistry" alias="ticketRegistry" /> > > > > <alias name="ticketGrantingTicketExpirationPolicy" > > alias="grantingTicketExpirationPolicy" /> > > <alias name="multiTimeUseOrTimeoutExpirationPolicy" > > alias="serviceTicketExpirationPolicy" /> > > > > <alias name="anyAuthenticationPolicy" alias="authenticationPolicy" > > /> > > <alias name="acceptAnyAuthenticationPolicyFactory" > > alias="authenticationPolicyFactory" /> > > > > <bean id="auditTrailManager" > > > > class="org.jasig.inspektr.audit.support.Slf4jLoggingAuditTrailManager" > > p:entrySeparator="${cas.audit.singleline.separator:|}" > > p:useSingleLine="${cas.audit.singleline:false}"/> > > > > <alias name="neverThrottle" alias="authenticationThrottle" /> > > > > <util:list id="monitorsList"> > > <ref bean="memoryMonitor" /> > > <ref bean="sessionMonitor" /> > > </util:list> > > > > <alias name="defaultPrincipalFactory" alias="principalFactory" /> > > <alias name="defaultAuthenticationTransactionManager" > > alias="authenticationTransactionManager" /> > > <alias name="defaultPrincipalElectionStrategy" > > alias="principalElectionStrategy" /> > > > > </beans> > > > > > > for HTTPSandIMAPS-10000001.json, > > { > > "@class" : "org.jasig.cas.services.RegexRegisteredService", > > "serviceId" : "^(https|imaps|http)://.*", /*add http*/ > > "name" : "HTTPS and IMAPS", > > "id" : 10000001, > > "description" : "This service definition authorized all application > > urls that support HTTPS and IMAPS protocols.", > > "proxyPolicy" : { > > "@class" : > > "org.jasig.cas.services.RefuseRegisteredServiceProxyPolicy" > > }, > > "evaluationOrder" : 10000, > > "usernameAttributeProvider" : { > > "@class" : > > "org.jasig.cas.services.DefaultRegisteredServiceUsernameProvider" > > }, > > "logoutType" : "BACK_CHANNEL", > > "attributeReleasePolicy" : { > > "@class" : > > "org.jasig.cas.services.ReturnAllowedAttributeReleasePolicy", > > "allowedAttributes" : [ "java.util.ArrayList", [ "name", "unitId", > > "accountStatus" ] ], /*allow some attribution.*/ > > "principalAttributesRepository" : { > > "@class" : > > "org.jasig.cas.authentication.principal.DefaultPrincipalAttributesRepository" > > }, > > "authorizedToReleaseCredentialPassword" : false, > > "authorizedToReleaseProxyGrantingTicket" : false > > }, > > "accessStrategy" : { > > "@class" : > > "org.jasig.cas.services.DefaultRegisteredServiceAccessStrategy", > > "enabled" : true, > > "ssoEnabled" : true > > } > > } > > > > -- > > You received this message because you are subscribed to the Google > > Groups "CAS Community" group. > > To unsubscribe from this group and stop receiving emails from it, send > > an email to [email protected]. > > Visit this group at > > https://groups.google.com/a/apereo.org/group/cas-user/. > > > > -- > > You received this message because you are subscribed to the Google > > Groups "CAS Community" group. > > To unsubscribe from this group and stop receiving emails from it, send > > an email to [email protected]. > > Visit this group at > > https://groups.google.com/a/apereo.org/group/cas-user/. > > > > -- > YunQiang Su -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
