On Tue, Jan 12, 2016 at 9:49 PM, YunQiang Su <[email protected]> wrote:
> On Tue, Jan 12, 2016 at 9:10 PM, Misagh Moayyed <[email protected]> wrote:
>> No. I meant this paragraph:
>>
>> "The principal resolution machinery provided by AuthenticationHandler
>> components should be used in preference to PrincipalResolver in any
>> situation where the former provides adequate functionality. If the principal
>> that is resolved by the authentication handler suffices, then a null value
>> may be passed in place of the resolver bean id"
>
> ohhh, null, thank you.
>
> <util:map id="authenticationHandlersResolvers">
>     ...
>     <entry key-ref="primaryAuthenticationHandler" value="#{null}" />

Ohhh, my fault, value-ref -> value

> </util:map>
>
> org.springframework.beans.factory.NoSuchBeanDefinitionException: No
> bean named 'null' is defined
>
>>
>>> -----Original Message-----
>>> From: YunQiang Su [mailto:[email protected]]
>>> Sent: Tuesday, January 12, 2016 5:56 AM
>>> To: Misagh Moayyed <[email protected]>
>>> Cc: CAS Community <[email protected]>
>>> Subject: Re: [cas-user] Cas 4.2 RC1 attributes get problem
>>>
>>> On Tue, Jan 12, 2016 at 8:26 PM, Misagh Moayyed <[email protected]>
>>> wrote:
>>> > Study
>>> > https://jasig.github.io/cas/4.2.x/installation/Configuring-Principal-R
>>> > esolution.html
>>>
>>> I see it, while still some confused.
>>>
>>> Did you mean this one?
>>>
>>> https://wiki.jasig.org/display/PDM15/LDAP+Attribute+Source
>>>
>>> and get
>>>
>>> Caused by:
>>> org.springframework.beans.factory.NoSuchBeanDefinitionException:
>>> No qualifying bean of type
>>> [org.jasig.services.persondir.IPersonAttributeDao] found for
>>> dependency: expected at least 1 bean which qualifies as autowire candidate
>>> for
>>> this dependency. Dependency annotations:
>>> {@org.springframework.beans.factory.annotation.Qualifier(value=attributeRep
>>> ository)}
>>>
>>> >
>>> >
>>> >
>>> > From: [email protected] [mailto:[email protected]] On Behalf Of
>>> > Yunqiang Su
>>> > Sent: Tuesday, January 12, 2016 12:34 AM
>>> > To: CAS Community <[email protected]>
>>> > Subject: [cas-user] Cas 4.2 RC1 attributes get problem
>>> >
>>> >
>>> >
>>> > I download and built cas 4.2 rc1, and modify some files.
>>> > It can be used to authorize while I cannot get other attribute.
>>> >
>>> > As catalina.out said,
>>> > ldapAuthenticationHandler can get these attributes, while on phpCAS, I
>>> > get something like this:
>>> >
>>> >
>>> > array(6) {
>>> >   ["accountStatus"]=&gt;
>>> >   string(13) "accountStatus"
>>> >   ["name"]=&gt;
>>> >   string(4) "name"
>>> >   ["authenticationDate"]=&gt;
>>> >   string(29) "2016-01-12T14:23:02.032+08:00"
>>> >   ["isFromNewLogin"]=&gt;
>>> >   string(4) "true"
>>> >   ["longTermAuthenticationRequestTokenUsed"]=&gt;
>>> >   string(5) "false"
>>> >   ["unitId"]=&gt;
>>> >   string(6) "unitId"
>>> > }
>>> >
>>> >
>>> > I think that the problem is caused by mis-configuration:
>>> > attributeRepository.
>>> > Any idea how to configure it?
>>> >
>>> > deployerConfigContext.xml
>>> >
>>> > <beans xmlns="http://www.springframework.org/schema/beans";
>>> >        xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance";
>>> >        xmlns:ldaptive="http://www.ldaptive.org/schema/spring-ext";
>>> >        xmlns:context="http://www.springframework.org/schema/context";
>>> >        xmlns:p="http://www.springframework.org/schema/p";
>>> >        xmlns:c="http://www.springframework.org/schema/c";
>>> >        xmlns:aop="http://www.springframework.org/schema/aop";
>>> >        xmlns:tx="http://www.springframework.org/schema/tx";
>>> >        xmlns:util="http://www.springframework.org/schema/util";
>>> >        xmlns:sec="http://www.springframework.org/schema/security";
>>> >        xsi:schemaLocation="http://www.springframework.org/schema/beans
>>> > http://www.springframework.org/schema/beans/spring-beans.xsd
>>> >        http://www.springframework.org/schema/tx
>>> > http://www.springframework.org/schema/tx/spring-tx.xsd
>>> >        http://www.springframework.org/schema/aop
>>> > http://www.springframework.org/schema/aop/spring-aop.xsd
>>> >        http://www.springframework.org/schema/context
>>> > http://www.springframework.org/schema/context/spring-context.xsd
>>> >        http://www.springframework.org/schema/security
>>> > http://www.springframework.org/schema/security/spring-security.xsd
>>> >        http://www.ldaptive.org/schema/spring-ext
>>> > http://www.ldaptive.org/schema/spring-ext.xsd
>>> >        http://www.springframework.org/schema/util
>>> > http://www.springframework.org/schema/util/spring-util.xsd";>
>>> >
>>> > <!-- auth with
>>> > http://jasig.github.io/cas/development/installation/LDAP-Authentication.html
>>> >        LDAP Requiring Authenticated Search
>>> > -->
>>> >     <bean id="ldapAuthenticationHandler"
>>> >     class="org.jasig.cas.authentication.LdapAuthenticationHandler"
>>> >           p:principalIdAttribute="uid"
>>> >           c:authenticator-ref="authenticator">
>>> >         <property name="principalAttributeMap">
>>> >         <map>
>>> >             <entry key="name" value="name" />
>>> >             <entry key="accountStatus" value="accountStatus" />
>>> >             <entry key="unitId" value="unitId" />
>>> >         </map>
>>> >         </property>
>>> >     </bean>
>>> >
>>> >     <ldaptive:bind-search-authenticator id="authenticator"
>>> >         ldapUrl="${ldap.url}"
>>> >         baseDn="${ldap.baseDn}"
>>> >         userFilter="${ldap.searchFilter}"
>>> >         bindDn="${ldap.managerDn}"
>>> >         bindCredential="${ldap.managerPassword}"
>>> >         connectTimeout="${ldap.connectTimeout}"
>>> >         useStartTLS="${ldap.useStartTLS}"
>>> >         blockWaitTime="${ldap.pool.blockWaitTime}"
>>> >         maxPoolSize="${ldap.pool.maxSize}"
>>> >         allowMultipleDns="${ldap.allowMultipleDns:false}"
>>> >         usePasswordPolicy="${ldap.usePpolicy:false}"
>>> >         minPoolSize="${ldap.pool.minSize}"
>>> >         validateOnCheckOut="${ldap.pool.validateOnCheckout}"
>>> >         validatePeriodically="${ldap.pool.validatePeriodically}"
>>> >         validatePeriod="${ldap.pool.validatePeriod}"
>>> >         idleTime="${ldap.pool.idleTime}"
>>> >         prunePeriod="${ldap.pool.prunePeriod}"
>>> >         failFastInitialize="true"
>>> >         subtreeSearch="${ldap.subtree.search:true}"
>>> >         useSSL="${ldap.use.ssl:false}"
>>> >     />
>>> >
>>> >     <util:map id="authenticationHandlersResolvers">
>>> >         <entry key-ref="proxyAuthenticationHandler"
>>> > value-ref="proxyPrincipalResolver" />
>>> >         <entry key-ref="primaryAuthenticationHandler"
>>> > value-ref="primaryPrincipalResolver" />
>>> >     </util:map>
>>> >     <util:list id="authenticationMetadataPopulators" />
>>> >
>>> > <!-- for attributions -->
>>> >     <bean id="attributeRepository"
>>> > class="org.jasig.services.persondir.support.NamedStubPersonAttributeDao"
>>> >           p:backingMap-ref="attrRepoBackingMap" />
>>> >     <util:map id="attrRepoBackingMap">
>>> >         <entry key="name" value="name" />
>>> >         <entry key="unitId" value="unitId" />
>>> >         <entry key="accountStatus" value="accountStatus" />
>>> >     </util:map>
>>> >
>>> >     <alias name="ldapAuthenticationHandler"
>>> > alias="primaryAuthenticationHandler" />
>>> >     <alias name="personDirectoryPrincipalResolver"
>>> > alias="primaryPrincipalResolver" />
>>> >
>>> >     <alias name="serviceThemeResolver" alias="themeResolver" />
>>> >
>>> >     <alias name="jsonServiceRegistryDao" alias="serviceRegistryDao" />
>>> >
>>> >     <alias name="defaultTicketRegistry" alias="ticketRegistry" />
>>> >
>>> >     <alias name="ticketGrantingTicketExpirationPolicy"
>>> > alias="grantingTicketExpirationPolicy" />
>>> >     <alias name="multiTimeUseOrTimeoutExpirationPolicy"
>>> > alias="serviceTicketExpirationPolicy" />
>>> >
>>> >     <alias name="anyAuthenticationPolicy" alias="authenticationPolicy"
>>> > />
>>> >     <alias name="acceptAnyAuthenticationPolicyFactory"
>>> > alias="authenticationPolicyFactory" />
>>> >
>>> >     <bean id="auditTrailManager"
>>> >
>>> > class="org.jasig.inspektr.audit.support.Slf4jLoggingAuditTrailManager"
>>> >           p:entrySeparator="${cas.audit.singleline.separator:|}"
>>> >           p:useSingleLine="${cas.audit.singleline:false}"/>
>>> >
>>> >     <alias name="neverThrottle" alias="authenticationThrottle" />
>>> >
>>> >     <util:list id="monitorsList">
>>> >         <ref bean="memoryMonitor" />
>>> >         <ref bean="sessionMonitor" />
>>> >     </util:list>
>>> >
>>> >     <alias name="defaultPrincipalFactory" alias="principalFactory" />
>>> >     <alias name="defaultAuthenticationTransactionManager"
>>> > alias="authenticationTransactionManager" />
>>> >     <alias name="defaultPrincipalElectionStrategy"
>>> > alias="principalElectionStrategy" />
>>> >
>>> > </beans>
>>> >
>>> >
>>> > for HTTPSandIMAPS-10000001.json,
>>> > {
>>> >   "@class" : "org.jasig.cas.services.RegexRegisteredService",
>>> >   "serviceId" : "^(https|imaps|http)://.*",       /*add http*/
>>> >   "name" : "HTTPS and IMAPS",
>>> >   "id" : 10000001,
>>> >   "description" : "This service definition authorized all application
>>> > urls that support HTTPS and IMAPS protocols.",
>>> >   "proxyPolicy" : {
>>> >     "@class" :
>>> > "org.jasig.cas.services.RefuseRegisteredServiceProxyPolicy"
>>> >   },
>>> >   "evaluationOrder" : 10000,
>>> >   "usernameAttributeProvider" : {
>>> >     "@class" :
>>> > "org.jasig.cas.services.DefaultRegisteredServiceUsernameProvider"
>>> >   },
>>> >   "logoutType" : "BACK_CHANNEL",
>>> >   "attributeReleasePolicy" : {
>>> >     "@class" :
>>> > "org.jasig.cas.services.ReturnAllowedAttributeReleasePolicy",
>>> >     "allowedAttributes" : [ "java.util.ArrayList", [ "name", "unitId",
>>> > "accountStatus" ] ],    /*allow some attribution.*/
>>> >     "principalAttributesRepository" : {
>>> >       "@class" :
>>> > "org.jasig.cas.authentication.principal.DefaultPrincipalAttributesRepository"
>>> >     },
>>> >     "authorizedToReleaseCredentialPassword" : false,
>>> >     "authorizedToReleaseProxyGrantingTicket" : false
>>> >   },
>>> >   "accessStrategy" : {
>>> >     "@class" :
>>> > "org.jasig.cas.services.DefaultRegisteredServiceAccessStrategy",
>>> >     "enabled" : true,
>>> >     "ssoEnabled" : true
>>> >   }
>>> > }
>>> >
>>> > --
>>> > You received this message because you are subscribed to the Google
>>> > Groups "CAS Community" group.
>>> > To unsubscribe from this group and stop receiving emails from it, send
>>> > an email to [email protected].
>>> > Visit this group at
>>> > https://groups.google.com/a/apereo.org/group/cas-user/.
>>> >
>>> > --
>>> > You received this message because you are subscribed to the Google
>>> > Groups "CAS Community" group.
>>> > To unsubscribe from this group and stop receiving emails from it, send
>>> > an email to [email protected].
>>> > Visit this group at
>>> > https://groups.google.com/a/apereo.org/group/cas-user/.
>>>
>>>
>>>
>>> --
>>> YunQiang Su
>>
>> --
>> You received this message because you are subscribed to the Google Groups 
>> "CAS Community" group.
>> To unsubscribe from this group and stop receiving emails from it, send an 
>> email to [email protected].
>> Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
>
>
>
> --
> YunQiang Su



-- 
YunQiang Su

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to