I’d have to see the full log to make a judgement here, but for others, by 
all means file issues. Turn up the logs for spring security and you should 
see more.



As for grants and authorities, you’re perfectly fine. Do include that in the 
issue.

--Misagh



From: Menno en Erla Avegaart [mailto:[email protected]]
Sent: Monday, February 6, 2017 1:25 PM
To: CAS Community <[email protected]>
Cc: [email protected]
Subject: Re: [cas-user] Spring security problems



Thanks, the first problem seems to be fixed now and I created an issue for 
6+7.



That leave me with the problem 2: After logging into any status page I get a 
401 error, even though the log shows that authorization was successful (I 
get "Executing authorization for expected admin roles [{}]", not followed by 
"User [{}] is not authorized to access the requested resource allowed to 
roles [{}]").



Also, I was looking at LdapAuthenticationProvider and wondered why you are 
adding the attributes as authorities:



authorities.addAll(profile.getAttributes().entrySet().stream().map(e -> new 
SimpleGrantedAuthority(e.getValue().toString())).collect(Collectors.toList()));



That just seems wrong. User attributes are not authorities, only roles are!



Op vrijdag 3 februari 2017 15:25:11 UTC+1 schreef Misagh Moayyed:

Quick update: testing this a bit more I did find a few anomalies. I’ll put 
aside some time to review and apply fixes and if you want to track progress, 
do please open up that issue.



Thanks.



--Misagh



From: Misagh Moayyed [mailto:[email protected] <javascript:> ]
Sent: Friday, February 3, 2017 2:34 PM
To: [email protected] <javascript:>
Subject: RE: [cas-user] Spring security problems





1. I configured security.basic.path=/cas/status/** and it triggers for 
Spring Boot endpoints (e.g. /cas/status/health), but it doesn't for 
/cas/status/dashboard. Am I missing a config option somewhere?



Possible. Difficult to say without seeing what the config looks like.



2. Are Spring Boot endpoints like /cas/status/health supposed to work?



Yes. Open issues if you find the opposite is true.



3. Yes, but if you do that you bypass Spring Security and no longer have to 
option to validate roles (see https://github.com/apereo/cas/issues/2335).



Cool. Sounds like a PR to me.



5. It does need the .type, because LdapAuthenticationProvider uses it.



Yes. See my previous comment.



6. LdapUserGroupsToRolesAuthorizationGenerator is the one that deals with 
groups, but because it inherits from 
LdapUserAttributesToRolesAuthorizationGenerator it also checks the 
roleAttribute (in my code I temporarily moved de roleAttribute code from 
LdapUserAttributesToRolesAuthorizationGenerator.generate() to 
addProfileRoles()).



If I am understanding you correctly, you’ll need to make sure only 
LdapUserAttributesToRolesAuthorizationGenerator is activated, and basically 
treat your groupAttribute as CAS’ roleAttribute if possible.









  _____

This email has been scanned for spam and viruses by Proofpoint Essentials. 
Click here 
<https://us2.proofpointessentials.com/index01.php?mod_id=11&mod_option=logitem&mail_id=1486383922-V5QlDmRl%2BfKa&r_address=mmoayyed%40unicon.net&report=1>
 
to report this email as spam.


=

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/00eb01d2807a%24aa2c6f90%24fe854eb0%24%40unicon.net.

Reply via email to