I'm testing the new Spring security integration in CAS 5.1.0-RC2-SNAPSHOT 
and fail to get it working.


Before I post this as a bug report I would like some feedback, because it 
fails so completely that I think I'm missing something...


My issues so far:

   1. Only the Spring Boot security endpoints trigger authentication, but 
   the classic CAS status pages (e.g. /cas/status/dashboard) do not. This 
   means there is no way to access them, unless you disable Spring Security 
   and use cas.adminPagesSecurity again.
   2. The Spring Boot security endpoints also don't work, because they are 
   not configured to supply information.
   3. It would be nice if you could select CAS authentication instead of 
   basic authentication in Spring Security.
   4. LdapAutenticationProvider validates roles based on 
   cas.adminPagesSecurity.adminRoles instead of management.security.roles (is 
   this wrong or does it just need documentation?).
   5. LdapUserAttributesToRolesAuthorizationGenerator always does a user 
   search and ignores cas.adminPagesSecurity.ldap.type. Does it really need to 
   fetch the user attributes again when 
   LdapAuthenticationProvider.authenticate just did that?
   6. LdapUserGroupsToRolesAuthorizationGenerator throws an 
   IllegalStateException when roleAttribute is not defined (our LDAP doesn't 
   have a roleAttribute, only a groupAttribute). Note: 
   CasWebApplicationSecurityConfiguration also checks the roleAttribute!
   7. Our baseDn for groups is different from the one for users. It would 
   be nice if a cas.adminPagesSecurity.ldap.ldapAuthz.groupBaseDn were added 
   (I currently need to specify a baseDn higher in the tree and do a subtree 
   search).


-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/c6d58f4b-a343-435b-9cf8-d508e8a7588c%40apereo.org.

Reply via email to