On Tue, Jan 12, 2016 at 9:49 PM, YunQiang Su <[email protected]> wrote: > On Tue, Jan 12, 2016 at 9:10 PM, Misagh Moayyed <[email protected]> wrote: >> No. I meant this paragraph: >> >> "The principal resolution machinery provided by AuthenticationHandler >> components should be used in preference to PrincipalResolver in any >> situation where the former provides adequate functionality. If the principal >> that is resolved by the authentication handler suffices, then a null value >> may be passed in place of the resolver bean id" > > ohhh, null, thank you. > > <util:map id="authenticationHandlersResolvers"> > ... > <entry key-ref="primaryAuthenticationHandler" value="#{null}" />
Ohhh, my fault, value-ref -> value > </util:map> > > org.springframework.beans.factory.NoSuchBeanDefinitionException: No > bean named 'null' is defined > >> >>> -----Original Message----- >>> From: YunQiang Su [mailto:[email protected]] >>> Sent: Tuesday, January 12, 2016 5:56 AM >>> To: Misagh Moayyed <[email protected]> >>> Cc: CAS Community <[email protected]> >>> Subject: Re: [cas-user] Cas 4.2 RC1 attributes get problem >>> >>> On Tue, Jan 12, 2016 at 8:26 PM, Misagh Moayyed <[email protected]> >>> wrote: >>> > Study >>> > https://jasig.github.io/cas/4.2.x/installation/Configuring-Principal-R >>> > esolution.html >>> >>> I see it, while still some confused. >>> >>> Did you mean this one? >>> >>> https://wiki.jasig.org/display/PDM15/LDAP+Attribute+Source >>> >>> and get >>> >>> Caused by: >>> org.springframework.beans.factory.NoSuchBeanDefinitionException: >>> No qualifying bean of type >>> [org.jasig.services.persondir.IPersonAttributeDao] found for >>> dependency: expected at least 1 bean which qualifies as autowire candidate >>> for >>> this dependency. Dependency annotations: >>> {@org.springframework.beans.factory.annotation.Qualifier(value=attributeRep >>> ository)} >>> >>> > >>> > >>> > >>> > From: [email protected] [mailto:[email protected]] On Behalf Of >>> > Yunqiang Su >>> > Sent: Tuesday, January 12, 2016 12:34 AM >>> > To: CAS Community <[email protected]> >>> > Subject: [cas-user] Cas 4.2 RC1 attributes get problem >>> > >>> > >>> > >>> > I download and built cas 4.2 rc1, and modify some files. >>> > It can be used to authorize while I cannot get other attribute. >>> > >>> > As catalina.out said, >>> > ldapAuthenticationHandler can get these attributes, while on phpCAS, I >>> > get something like this: >>> > >>> > >>> > array(6) { >>> > ["accountStatus"]=> >>> > string(13) "accountStatus" >>> > ["name"]=> >>> > string(4) "name" >>> > ["authenticationDate"]=> >>> > string(29) "2016-01-12T14:23:02.032+08:00" >>> > ["isFromNewLogin"]=> >>> > string(4) "true" >>> > ["longTermAuthenticationRequestTokenUsed"]=> >>> > string(5) "false" >>> > ["unitId"]=> >>> > string(6) "unitId" >>> > } >>> > >>> > >>> > I think that the problem is caused by mis-configuration: >>> > attributeRepository. >>> > Any idea how to configure it? >>> > >>> > deployerConfigContext.xml >>> > >>> > <beans xmlns="http://www.springframework.org/schema/beans" >>> > xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" >>> > xmlns:ldaptive="http://www.ldaptive.org/schema/spring-ext" >>> > xmlns:context="http://www.springframework.org/schema/context" >>> > xmlns:p="http://www.springframework.org/schema/p" >>> > xmlns:c="http://www.springframework.org/schema/c" >>> > xmlns:aop="http://www.springframework.org/schema/aop" >>> > xmlns:tx="http://www.springframework.org/schema/tx" >>> > xmlns:util="http://www.springframework.org/schema/util" >>> > xmlns:sec="http://www.springframework.org/schema/security" >>> > xsi:schemaLocation="http://www.springframework.org/schema/beans >>> > http://www.springframework.org/schema/beans/spring-beans.xsd >>> > http://www.springframework.org/schema/tx >>> > http://www.springframework.org/schema/tx/spring-tx.xsd >>> > http://www.springframework.org/schema/aop >>> > http://www.springframework.org/schema/aop/spring-aop.xsd >>> > http://www.springframework.org/schema/context >>> > http://www.springframework.org/schema/context/spring-context.xsd >>> > http://www.springframework.org/schema/security >>> > http://www.springframework.org/schema/security/spring-security.xsd >>> > http://www.ldaptive.org/schema/spring-ext >>> > http://www.ldaptive.org/schema/spring-ext.xsd >>> > http://www.springframework.org/schema/util >>> > http://www.springframework.org/schema/util/spring-util.xsd"> >>> > >>> > <!-- auth with >>> > http://jasig.github.io/cas/development/installation/LDAP-Authentication.html >>> > LDAP Requiring Authenticated Search >>> > --> >>> > <bean id="ldapAuthenticationHandler" >>> > class="org.jasig.cas.authentication.LdapAuthenticationHandler" >>> > p:principalIdAttribute="uid" >>> > c:authenticator-ref="authenticator"> >>> > <property name="principalAttributeMap"> >>> > <map> >>> > <entry key="name" value="name" /> >>> > <entry key="accountStatus" value="accountStatus" /> >>> > <entry key="unitId" value="unitId" /> >>> > </map> >>> > </property> >>> > </bean> >>> > >>> > <ldaptive:bind-search-authenticator id="authenticator" >>> > ldapUrl="${ldap.url}" >>> > baseDn="${ldap.baseDn}" >>> > userFilter="${ldap.searchFilter}" >>> > bindDn="${ldap.managerDn}" >>> > bindCredential="${ldap.managerPassword}" >>> > connectTimeout="${ldap.connectTimeout}" >>> > useStartTLS="${ldap.useStartTLS}" >>> > blockWaitTime="${ldap.pool.blockWaitTime}" >>> > maxPoolSize="${ldap.pool.maxSize}" >>> > allowMultipleDns="${ldap.allowMultipleDns:false}" >>> > usePasswordPolicy="${ldap.usePpolicy:false}" >>> > minPoolSize="${ldap.pool.minSize}" >>> > validateOnCheckOut="${ldap.pool.validateOnCheckout}" >>> > validatePeriodically="${ldap.pool.validatePeriodically}" >>> > validatePeriod="${ldap.pool.validatePeriod}" >>> > idleTime="${ldap.pool.idleTime}" >>> > prunePeriod="${ldap.pool.prunePeriod}" >>> > failFastInitialize="true" >>> > subtreeSearch="${ldap.subtree.search:true}" >>> > useSSL="${ldap.use.ssl:false}" >>> > /> >>> > >>> > <util:map id="authenticationHandlersResolvers"> >>> > <entry key-ref="proxyAuthenticationHandler" >>> > value-ref="proxyPrincipalResolver" /> >>> > <entry key-ref="primaryAuthenticationHandler" >>> > value-ref="primaryPrincipalResolver" /> >>> > </util:map> >>> > <util:list id="authenticationMetadataPopulators" /> >>> > >>> > <!-- for attributions --> >>> > <bean id="attributeRepository" >>> > class="org.jasig.services.persondir.support.NamedStubPersonAttributeDao" >>> > p:backingMap-ref="attrRepoBackingMap" /> >>> > <util:map id="attrRepoBackingMap"> >>> > <entry key="name" value="name" /> >>> > <entry key="unitId" value="unitId" /> >>> > <entry key="accountStatus" value="accountStatus" /> >>> > </util:map> >>> > >>> > <alias name="ldapAuthenticationHandler" >>> > alias="primaryAuthenticationHandler" /> >>> > <alias name="personDirectoryPrincipalResolver" >>> > alias="primaryPrincipalResolver" /> >>> > >>> > <alias name="serviceThemeResolver" alias="themeResolver" /> >>> > >>> > <alias name="jsonServiceRegistryDao" alias="serviceRegistryDao" /> >>> > >>> > <alias name="defaultTicketRegistry" alias="ticketRegistry" /> >>> > >>> > <alias name="ticketGrantingTicketExpirationPolicy" >>> > alias="grantingTicketExpirationPolicy" /> >>> > <alias name="multiTimeUseOrTimeoutExpirationPolicy" >>> > alias="serviceTicketExpirationPolicy" /> >>> > >>> > <alias name="anyAuthenticationPolicy" alias="authenticationPolicy" >>> > /> >>> > <alias name="acceptAnyAuthenticationPolicyFactory" >>> > alias="authenticationPolicyFactory" /> >>> > >>> > <bean id="auditTrailManager" >>> > >>> > class="org.jasig.inspektr.audit.support.Slf4jLoggingAuditTrailManager" >>> > p:entrySeparator="${cas.audit.singleline.separator:|}" >>> > p:useSingleLine="${cas.audit.singleline:false}"/> >>> > >>> > <alias name="neverThrottle" alias="authenticationThrottle" /> >>> > >>> > <util:list id="monitorsList"> >>> > <ref bean="memoryMonitor" /> >>> > <ref bean="sessionMonitor" /> >>> > </util:list> >>> > >>> > <alias name="defaultPrincipalFactory" alias="principalFactory" /> >>> > <alias name="defaultAuthenticationTransactionManager" >>> > alias="authenticationTransactionManager" /> >>> > <alias name="defaultPrincipalElectionStrategy" >>> > alias="principalElectionStrategy" /> >>> > >>> > </beans> >>> > >>> > >>> > for HTTPSandIMAPS-10000001.json, >>> > { >>> > "@class" : "org.jasig.cas.services.RegexRegisteredService", >>> > "serviceId" : "^(https|imaps|http)://.*", /*add http*/ >>> > "name" : "HTTPS and IMAPS", >>> > "id" : 10000001, >>> > "description" : "This service definition authorized all application >>> > urls that support HTTPS and IMAPS protocols.", >>> > "proxyPolicy" : { >>> > "@class" : >>> > "org.jasig.cas.services.RefuseRegisteredServiceProxyPolicy" >>> > }, >>> > "evaluationOrder" : 10000, >>> > "usernameAttributeProvider" : { >>> > "@class" : >>> > "org.jasig.cas.services.DefaultRegisteredServiceUsernameProvider" >>> > }, >>> > "logoutType" : "BACK_CHANNEL", >>> > "attributeReleasePolicy" : { >>> > "@class" : >>> > "org.jasig.cas.services.ReturnAllowedAttributeReleasePolicy", >>> > "allowedAttributes" : [ "java.util.ArrayList", [ "name", "unitId", >>> > "accountStatus" ] ], /*allow some attribution.*/ >>> > "principalAttributesRepository" : { >>> > "@class" : >>> > "org.jasig.cas.authentication.principal.DefaultPrincipalAttributesRepository" >>> > }, >>> > "authorizedToReleaseCredentialPassword" : false, >>> > "authorizedToReleaseProxyGrantingTicket" : false >>> > }, >>> > "accessStrategy" : { >>> > "@class" : >>> > "org.jasig.cas.services.DefaultRegisteredServiceAccessStrategy", >>> > "enabled" : true, >>> > "ssoEnabled" : true >>> > } >>> > } >>> > >>> > -- >>> > You received this message because you are subscribed to the Google >>> > Groups "CAS Community" group. >>> > To unsubscribe from this group and stop receiving emails from it, send >>> > an email to [email protected]. >>> > Visit this group at >>> > https://groups.google.com/a/apereo.org/group/cas-user/. >>> > >>> > -- >>> > You received this message because you are subscribed to the Google >>> > Groups "CAS Community" group. >>> > To unsubscribe from this group and stop receiving emails from it, send >>> > an email to [email protected]. >>> > Visit this group at >>> > https://groups.google.com/a/apereo.org/group/cas-user/. >>> >>> >>> >>> -- >>> YunQiang Su >> >> -- >> You received this message because you are subscribed to the Google Groups >> "CAS Community" group. >> To unsubscribe from this group and stop receiving emails from it, send an >> email to [email protected]. >> Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/. > > > > -- > YunQiang Su -- YunQiang Su -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
