On Tue, Jan 12, 2016 at 9:10 PM, Misagh Moayyed <[email protected]> wrote:
> No. I meant this paragraph:
>
> "The principal resolution machinery provided by AuthenticationHandler
> components should be used in preference to PrincipalResolver in any
> situation where the former provides adequate functionality. If the principal
> that is resolved by the authentication handler suffices, then a null value
> may be passed in place of the resolver bean id"
ohhh, null, thank you.
<util:map id="authenticationHandlersResolvers">
...
<entry key-ref="primaryAuthenticationHandler" value="#{null}" />
</util:map>
org.springframework.beans.factory.NoSuchBeanDefinitionException: No
bean named 'null' is defined
>
>> -----Original Message-----
>> From: YunQiang Su [mailto:[email protected]]
>> Sent: Tuesday, January 12, 2016 5:56 AM
>> To: Misagh Moayyed <[email protected]>
>> Cc: CAS Community <[email protected]>
>> Subject: Re: [cas-user] Cas 4.2 RC1 attributes get problem
>>
>> On Tue, Jan 12, 2016 at 8:26 PM, Misagh Moayyed <[email protected]>
>> wrote:
>> > Study
>> > https://jasig.github.io/cas/4.2.x/installation/Configuring-Principal-R
>> > esolution.html
>>
>> I see it, while still some confused.
>>
>> Did you mean this one?
>>
>> https://wiki.jasig.org/display/PDM15/LDAP+Attribute+Source
>>
>> and get
>>
>> Caused by:
>> org.springframework.beans.factory.NoSuchBeanDefinitionException:
>> No qualifying bean of type
>> [org.jasig.services.persondir.IPersonAttributeDao] found for
>> dependency: expected at least 1 bean which qualifies as autowire candidate
>> for
>> this dependency. Dependency annotations:
>> {@org.springframework.beans.factory.annotation.Qualifier(value=attributeRep
>> ository)}
>>
>> >
>> >
>> >
>> > From: [email protected] [mailto:[email protected]] On Behalf Of
>> > Yunqiang Su
>> > Sent: Tuesday, January 12, 2016 12:34 AM
>> > To: CAS Community <[email protected]>
>> > Subject: [cas-user] Cas 4.2 RC1 attributes get problem
>> >
>> >
>> >
>> > I download and built cas 4.2 rc1, and modify some files.
>> > It can be used to authorize while I cannot get other attribute.
>> >
>> > As catalina.out said,
>> > ldapAuthenticationHandler can get these attributes, while on phpCAS, I
>> > get something like this:
>> >
>> >
>> > array(6) {
>> > ["accountStatus"]=>
>> > string(13) "accountStatus"
>> > ["name"]=>
>> > string(4) "name"
>> > ["authenticationDate"]=>
>> > string(29) "2016-01-12T14:23:02.032+08:00"
>> > ["isFromNewLogin"]=>
>> > string(4) "true"
>> > ["longTermAuthenticationRequestTokenUsed"]=>
>> > string(5) "false"
>> > ["unitId"]=>
>> > string(6) "unitId"
>> > }
>> >
>> >
>> > I think that the problem is caused by mis-configuration:
>> > attributeRepository.
>> > Any idea how to configure it?
>> >
>> > deployerConfigContext.xml
>> >
>> > <beans xmlns="http://www.springframework.org/schema/beans"
>> > xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
>> > xmlns:ldaptive="http://www.ldaptive.org/schema/spring-ext"
>> > xmlns:context="http://www.springframework.org/schema/context"
>> > xmlns:p="http://www.springframework.org/schema/p"
>> > xmlns:c="http://www.springframework.org/schema/c"
>> > xmlns:aop="http://www.springframework.org/schema/aop"
>> > xmlns:tx="http://www.springframework.org/schema/tx"
>> > xmlns:util="http://www.springframework.org/schema/util"
>> > xmlns:sec="http://www.springframework.org/schema/security"
>> > xsi:schemaLocation="http://www.springframework.org/schema/beans
>> > http://www.springframework.org/schema/beans/spring-beans.xsd
>> > http://www.springframework.org/schema/tx
>> > http://www.springframework.org/schema/tx/spring-tx.xsd
>> > http://www.springframework.org/schema/aop
>> > http://www.springframework.org/schema/aop/spring-aop.xsd
>> > http://www.springframework.org/schema/context
>> > http://www.springframework.org/schema/context/spring-context.xsd
>> > http://www.springframework.org/schema/security
>> > http://www.springframework.org/schema/security/spring-security.xsd
>> > http://www.ldaptive.org/schema/spring-ext
>> > http://www.ldaptive.org/schema/spring-ext.xsd
>> > http://www.springframework.org/schema/util
>> > http://www.springframework.org/schema/util/spring-util.xsd">
>> >
>> > <!-- auth with
>> > http://jasig.github.io/cas/development/installation/LDAP-Authentication.html
>> > LDAP Requiring Authenticated Search
>> > -->
>> > <bean id="ldapAuthenticationHandler"
>> > class="org.jasig.cas.authentication.LdapAuthenticationHandler"
>> > p:principalIdAttribute="uid"
>> > c:authenticator-ref="authenticator">
>> > <property name="principalAttributeMap">
>> > <map>
>> > <entry key="name" value="name" />
>> > <entry key="accountStatus" value="accountStatus" />
>> > <entry key="unitId" value="unitId" />
>> > </map>
>> > </property>
>> > </bean>
>> >
>> > <ldaptive:bind-search-authenticator id="authenticator"
>> > ldapUrl="${ldap.url}"
>> > baseDn="${ldap.baseDn}"
>> > userFilter="${ldap.searchFilter}"
>> > bindDn="${ldap.managerDn}"
>> > bindCredential="${ldap.managerPassword}"
>> > connectTimeout="${ldap.connectTimeout}"
>> > useStartTLS="${ldap.useStartTLS}"
>> > blockWaitTime="${ldap.pool.blockWaitTime}"
>> > maxPoolSize="${ldap.pool.maxSize}"
>> > allowMultipleDns="${ldap.allowMultipleDns:false}"
>> > usePasswordPolicy="${ldap.usePpolicy:false}"
>> > minPoolSize="${ldap.pool.minSize}"
>> > validateOnCheckOut="${ldap.pool.validateOnCheckout}"
>> > validatePeriodically="${ldap.pool.validatePeriodically}"
>> > validatePeriod="${ldap.pool.validatePeriod}"
>> > idleTime="${ldap.pool.idleTime}"
>> > prunePeriod="${ldap.pool.prunePeriod}"
>> > failFastInitialize="true"
>> > subtreeSearch="${ldap.subtree.search:true}"
>> > useSSL="${ldap.use.ssl:false}"
>> > />
>> >
>> > <util:map id="authenticationHandlersResolvers">
>> > <entry key-ref="proxyAuthenticationHandler"
>> > value-ref="proxyPrincipalResolver" />
>> > <entry key-ref="primaryAuthenticationHandler"
>> > value-ref="primaryPrincipalResolver" />
>> > </util:map>
>> > <util:list id="authenticationMetadataPopulators" />
>> >
>> > <!-- for attributions -->
>> > <bean id="attributeRepository"
>> > class="org.jasig.services.persondir.support.NamedStubPersonAttributeDao"
>> > p:backingMap-ref="attrRepoBackingMap" />
>> > <util:map id="attrRepoBackingMap">
>> > <entry key="name" value="name" />
>> > <entry key="unitId" value="unitId" />
>> > <entry key="accountStatus" value="accountStatus" />
>> > </util:map>
>> >
>> > <alias name="ldapAuthenticationHandler"
>> > alias="primaryAuthenticationHandler" />
>> > <alias name="personDirectoryPrincipalResolver"
>> > alias="primaryPrincipalResolver" />
>> >
>> > <alias name="serviceThemeResolver" alias="themeResolver" />
>> >
>> > <alias name="jsonServiceRegistryDao" alias="serviceRegistryDao" />
>> >
>> > <alias name="defaultTicketRegistry" alias="ticketRegistry" />
>> >
>> > <alias name="ticketGrantingTicketExpirationPolicy"
>> > alias="grantingTicketExpirationPolicy" />
>> > <alias name="multiTimeUseOrTimeoutExpirationPolicy"
>> > alias="serviceTicketExpirationPolicy" />
>> >
>> > <alias name="anyAuthenticationPolicy" alias="authenticationPolicy"
>> > />
>> > <alias name="acceptAnyAuthenticationPolicyFactory"
>> > alias="authenticationPolicyFactory" />
>> >
>> > <bean id="auditTrailManager"
>> >
>> > class="org.jasig.inspektr.audit.support.Slf4jLoggingAuditTrailManager"
>> > p:entrySeparator="${cas.audit.singleline.separator:|}"
>> > p:useSingleLine="${cas.audit.singleline:false}"/>
>> >
>> > <alias name="neverThrottle" alias="authenticationThrottle" />
>> >
>> > <util:list id="monitorsList">
>> > <ref bean="memoryMonitor" />
>> > <ref bean="sessionMonitor" />
>> > </util:list>
>> >
>> > <alias name="defaultPrincipalFactory" alias="principalFactory" />
>> > <alias name="defaultAuthenticationTransactionManager"
>> > alias="authenticationTransactionManager" />
>> > <alias name="defaultPrincipalElectionStrategy"
>> > alias="principalElectionStrategy" />
>> >
>> > </beans>
>> >
>> >
>> > for HTTPSandIMAPS-10000001.json,
>> > {
>> > "@class" : "org.jasig.cas.services.RegexRegisteredService",
>> > "serviceId" : "^(https|imaps|http)://.*", /*add http*/
>> > "name" : "HTTPS and IMAPS",
>> > "id" : 10000001,
>> > "description" : "This service definition authorized all application
>> > urls that support HTTPS and IMAPS protocols.",
>> > "proxyPolicy" : {
>> > "@class" :
>> > "org.jasig.cas.services.RefuseRegisteredServiceProxyPolicy"
>> > },
>> > "evaluationOrder" : 10000,
>> > "usernameAttributeProvider" : {
>> > "@class" :
>> > "org.jasig.cas.services.DefaultRegisteredServiceUsernameProvider"
>> > },
>> > "logoutType" : "BACK_CHANNEL",
>> > "attributeReleasePolicy" : {
>> > "@class" :
>> > "org.jasig.cas.services.ReturnAllowedAttributeReleasePolicy",
>> > "allowedAttributes" : [ "java.util.ArrayList", [ "name", "unitId",
>> > "accountStatus" ] ], /*allow some attribution.*/
>> > "principalAttributesRepository" : {
>> > "@class" :
>> > "org.jasig.cas.authentication.principal.DefaultPrincipalAttributesRepository"
>> > },
>> > "authorizedToReleaseCredentialPassword" : false,
>> > "authorizedToReleaseProxyGrantingTicket" : false
>> > },
>> > "accessStrategy" : {
>> > "@class" :
>> > "org.jasig.cas.services.DefaultRegisteredServiceAccessStrategy",
>> > "enabled" : true,
>> > "ssoEnabled" : true
>> > }
>> > }
>> >
>> > --
>> > You received this message because you are subscribed to the Google
>> > Groups "CAS Community" group.
>> > To unsubscribe from this group and stop receiving emails from it, send
>> > an email to [email protected].
>> > Visit this group at
>> > https://groups.google.com/a/apereo.org/group/cas-user/.
>> >
>> > --
>> > You received this message because you are subscribed to the Google
>> > Groups "CAS Community" group.
>> > To unsubscribe from this group and stop receiving emails from it, send
>> > an email to [email protected].
>> > Visit this group at
>> > https://groups.google.com/a/apereo.org/group/cas-user/.
>>
>>
>>
>> --
>> YunQiang Su
>
> --
> You received this message because you are subscribed to the Google Groups
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
--
YunQiang Su
--
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.