Hi, 1. I configured security.basic.path=/cas/status/** and it triggers for Spring Boot endpoints (e.g. /cas/status/health), but it doesn't for /cas/status/dashboard. Am I missing a config option somewhere? 2. Are Spring Boot endpoints like /cas/status/health supposed to work? 3. Yes, but if you do that you bypass Spring Security and no longer have to option to validate roles (see https://github.com/apereo/cas/issues/2335). 5. It does need the .type, because LdapAuthenticationProvider uses it. 6. LdapUserGroupsToRolesAuthorizationGenerator is the one that deals with groups, but because it inherits from LdapUserAttributesToRolesAuthorizationGenerator it also checks the roleAttribute (in my code I temporarily moved de roleAttribute code from LdapUserAttributesToRolesAuthorizationGenerator.generate() to addProfileRoles()).
Thanks, Menno Op vrijdag 3 februari 2017 13:09:50 UTC+1 schreef Misagh Moayyed: > > 1. Only the Spring Boot security endpoints trigger authentication, > but the classic CAS status pages (e.g. /cas/status/dashboard) do not. This > means there is no way to access them, unless you disable Spring Security > and use cas.adminPagesSecurity again. > > You’ll need to map the endpoints in the settings to catch /cas/status/**. > > 2. The Spring Boot security endpoints also don't work, because they > are not configured to supply information. > > See above. > > 3. It would be nice if you could select CAS authentication instead of > basic authentication in Spring Security. > > Already possible. See settings. > > 4. LdapAutenticationProvider validates roles based on > cas.adminPagesSecurity.adminRoles instead of management.security.roles (is > this wrong or does it just need documentation?). > > Probably a bug. > > 5. LdapUserAttributesToRolesAuthorizationGenerator always does a user > search and ignores cas.adminPagesSecurity.ldap.type. Does it really need to > fetch the user attributes again when > LdapAuthenticationProvider.authenticate just did that? > > Don’t think it needs the type there. Type is only used for authN. > > 6. LdapUserGroupsToRolesAuthorizationGenerator throws an > IllegalStateException when roleAttribute is not defined (our LDAP doesn't > have a roleAttribute, only a groupAttribute). Note: > CasWebApplicationSecurityConfiguration also checks the roleAttribute! > > You’d want to configure it such that the roles are ignored via the other > generator. Activate the one that deals with groups only. > > 7. Our baseDn for groups is different from the one for users. It > would be nice if a cas.adminPagesSecurity.ldap.ldapAuthz.groupBaseDn were > added (I currently need to specify a baseDn higher in the tree and do a > subtree search). > > Sure. Submit a PR. > > > > -- > - CAS gitter chatroom: https://gitter.im/apereo/cas > - CAS mailing list guidelines: > https://apereo.github.io/cas/Mailing-Lists.html > - CAS documentation website: https://apereo.github.io/cas > - CAS project website: https://github.com/apereo/cas > --- > You received this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected] <javascript:>. > To view this discussion on the web visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/c6d58f4b-a343-435b-9cf8-d508e8a7588c%40apereo.org > > <https://groups.google.com/a/apereo.org/d/msgid/cas-user/c6d58f4b-a343-435b-9cf8-d508e8a7588c%40apereo.org?utm_medium=email&utm_source=footer> > . > -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/e90a45c8-e12a-4a81-9d0d-cc8fe42d4508%40apereo.org.
