1. I configured security.basic.path=/cas/status/** and it triggers for Spring Boot endpoints (e.g. /cas/status/health), but it doesn't for /cas/status/dashboard. Am I missing a config option somewhere?
Possible. Difficult to say without seeing what the config looks like. 2. Are Spring Boot endpoints like /cas/status/health supposed to work? Yes. Open issues if you find the opposite is true. 3. Yes, but if you do that you bypass Spring Security and no longer have to option to validate roles (see https://github.com/apereo/cas/issues/2335). Cool. Sounds like a PR to me. 5. It does need the .type, because LdapAuthenticationProvider uses it. See. See my previous comment. 6. LdapUserGroupsToRolesAuthorizationGenerator is the one that deals with groups, but because it inherits from LdapUserAttributesToRolesAuthorizationGenerator it also checks the roleAttribute (in my code I temporarily moved de roleAttribute code from LdapUserAttributesToRolesAuthorizationGenerator.generate() to addProfileRoles()). If I am understanding you correctly, you’ll need to make sure only LdapUserAttributesToRolesAuthorizationGenerator is activated, and basically treat your groupAttribute as CAS’ roleAttribute if possible. -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/010601d27e22%242e101740%248a3045c0%24%40unicon.net.
