I'm testing the new Spring security integration in CAS 5.1.0-RC2-SNAPSHOT and fail to get it working.
Before I post this as a bug report I would like some feedback, because it fails so completely that I think I'm missing something... My issues so far: 1. Only the Spring Boot security endpoints trigger authentication, but the classic CAS status pages (e.g. /cas/status/dashboard) do not. This means there is no way to access them, unless you disable Spring Security and use cas.adminPagesSecurity again. 2. The Spring Boot security endpoints also don't work, because they are not configured to supply information. 3. It would be nice if you could select CAS authentication instead of basic authentication in Spring Security. 4. LdapAutenticationProvider validates roles based on cas.adminPagesSecurity.adminRoles instead of management.security.roles (is this wrong or does it just need documentation?). 5. LdapUserAttributesToRolesAuthorizationGenerator always does a user search and ignores cas.adminPagesSecurity.ldap.type. Does it really need to fetch the user attributes again when LdapAuthenticationProvider.authenticate just did that? 6. LdapUserGroupsToRolesAuthorizationGenerator throws an IllegalStateException when roleAttribute is not defined (our LDAP doesn't have a roleAttribute, only a groupAttribute). Note: CasWebApplicationSecurityConfiguration also checks the roleAttribute! 7. Our baseDn for groups is different from the one for users. It would be nice if a cas.adminPagesSecurity.ldap.ldapAuthz.groupBaseDn were added (I currently need to specify a baseDn higher in the tree and do a subtree search). -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/c6d58f4b-a343-435b-9cf8-d508e8a7588c%40apereo.org.
