I have been trying to try this option for securing endpoints with spring 
security mentioned at the following links:

https://apereo.github.io/cas/5.1.x/installation/Monitoring-Statistics.html#spring-security
and
https://apereo.github.io/cas/5.1.x/installation/Configuration-Properties.html#securing-endpoints-with-spring-security

I have added the dependency to my pom.xml and I have tried adding the 
following to my cas.properties:

endpoints.enabled=true
endpoints.sensitive=true
cas.monitor.endpoints.enabled=true
cas.monitor.endpoints.sensitive=true
security.user.name=master
security.user.password=
security.user.role=ACTUATOR
security.basic.authorizeMode=role
security.basic.enabled=true
security.basic.path=/cas/status/**
security.basic.realm=CAS
security.filterOrder=0
security.requireSsl=false
security.sessions=if_required

But when I navigate to http://localhost:8080/cas/status I get the dreaded 
"You did not say the magic word" page.  Also, a password is supposed to 
(accordingly to the links above) be output to the logs but it isn't there.

I was expecting to have the web browser prompt me for a username/password 
and be able to put in the master for the username and a password from the 
logs but I don't get a password prompt at all.

Note that I also tried just setting a password using security.user.password 
but that seems to have no effect either.

Am I approach this incorrectly?  What am I missing?

Thanks!

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/29893cbc-d172-4299-b237-9e8570644c4a%40apereo.org.

Reply via email to