1. I configured security.basic.path=/cas/status/** and it triggers for 
Spring Boot endpoints (e.g. /cas/status/health), but it doesn't for 
/cas/status/dashboard. Am I missing a config option somewhere?



Possible. Difficult to say without seeing what the config looks like.



2. Are Spring Boot endpoints like /cas/status/health supposed to work?



Yes. Open issues if you find the opposite is true.



3. Yes, but if you do that you bypass Spring Security and no longer have to 
option to validate roles (see https://github.com/apereo/cas/issues/2335).



Cool. Sounds like a PR to me.



5. It does need the .type, because LdapAuthenticationProvider uses it.



See. See my previous comment.



6. LdapUserGroupsToRolesAuthorizationGenerator is the one that deals with 
groups, but because it inherits from 
LdapUserAttributesToRolesAuthorizationGenerator it also checks the 
roleAttribute (in my code I temporarily moved de roleAttribute code from 
LdapUserAttributesToRolesAuthorizationGenerator.generate() to 
addProfileRoles()).



If I am understanding you correctly, you’ll need to make sure only 
LdapUserAttributesToRolesAuthorizationGenerator is activated, and basically 
treat your groupAttribute as CAS’ roleAttribute if possible.





-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/010601d27e22%242e101740%248a3045c0%24%40unicon.net.

Reply via email to