Caching can be controlled but it’s today based on a per-app basis: 
https://apereo.github.io/cas/5.2.x/integration/Attribute-Release-Caching.html 

Also, it might better to review this page for options that handle bypass more 
dynamically: 
https://apereo.github.io/cas/5.2.x/installation/Configuring-Multifactor-Authentication-Bypass.html
 

…which should get invoked every time. 

--Misagh 

> From: "Adam Causey" <[email protected]>
> To: [email protected]
> Sent: Tuesday, December 5, 2017 1:39:54 PM
> Subject: Re: [cas-user] Customized MFA bypass in CAS 5.1.x

> Is there a way to not cache the attributes that are retrieved via a Groovy
> script? I noticed they are cached, and I need the bypass check to occur on
> every login, including the SSO logins.

> Thanks,
> Adam

> On Thu, Oct 19, 2017 at 1:14 PM, Misagh Moayyed < [email protected] > wrote:

>> Sorry; too many versions to keep track of. I was of thinking of 5.2 where you
>> can hit a rest endpoint and have it return attributes for you. No such thing 
>> in
>> 5.1. My bad. Alternatively, you write a groovy script that would do the same.
>> https://apereo.github.io/cas/5.1.x/installation/Configuration-Properties.html#groovy

>>> From: "Adam Causey" < [email protected] >
>>> To: [email protected]
>>> Sent: Thursday, October 19, 2017 9:59:05 AM
>>> Subject: Re: [cas-user] Customized MFA bypass in CAS 5.1.x

>>> How and where would I populate the Principal? Are there any examples you 
>>> could
>>> provide.

>>> Thanks,
>>> Adam

>>> On Thu, Oct 19, 2017 at 12:46 PM, Misagh Moayyed < [email protected] > 
>>> wrote:

>>>> Not unless you write your own trigger. One other option would be to make 
>>>> the
>>>> REST call and populate the principal with an attribute that says 
>>>> "bypass=true".
>>>> Then let the bypass logic use that attribute. Likely more performant.

>>>>> From: "Adam Causey" < [email protected] >
>>>>> To: [email protected]
>>>>> Sent: Thursday, October 19, 2017 8:52:20 AM
>>>>> Subject: [cas-user] Customized MFA bypass in CAS 5.1.x

>>>>> Is there a way to add our own custom bypass logic to CAS 5.1.x? 
>>>>> Specifically I
>>>>> would like to make a call to a RESTful API that returns a boolean value 
>>>>> that
>>>>> says whether the user can bypass or not.

>>>>> Thanks,
>>>>> Adam

>>>>> --
>>>>> - Website: https://apereo.github.io/cas
>>>>> - Gitter Chatroom: https://gitter.im/apereo/cas
>>>>> - List Guidelines: https://goo.gl/1VRrw7
>>>>> - Contributions: https://goo.gl/mh7qDG
>>>>> ---
>>>>> You received this message because you are subscribed to the Google Groups 
>>>>> "CAS
>>>>> Community" group.
>>>>> To unsubscribe from this group and stop receiving emails from it, send an 
>>>>> email
>>>>> to [email protected] .
>>>>> To view this discussion on the web visit
>>>>> https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAN6MV5ON1ibwsupJjYCJ2cnF3MA4OXnzoqH%2B29pwiP8OLY%2BX2Q%40mail.gmail.com
>>>>> .

>>>> --
>>>> --Misagh

>>>> --
>>>> - Website: https://apereo.github.io/cas
>>>> - Gitter Chatroom: https://gitter.im/apereo/cas
>>>> - List Guidelines: https://goo.gl/1VRrw7
>>>> - Contributions: https://goo.gl/mh7qDG
>>>> ---
>>>> You received this message because you are subscribed to the Google Groups 
>>>> "CAS
>>>> Community" group.
>>>> To unsubscribe from this group and stop receiving emails from it, send an 
>>>> email
>>>> to [email protected] .
>>>> To view this discussion on the web visit
>>>> https://groups.google.com/a/apereo.org/d/msgid/cas-user/1598432640.5707319.1508431562461.JavaMail.zimbra%40unicon.net
>>>> .

>>> --
>>> - Website: https://apereo.github.io/cas
>>> - Gitter Chatroom: https://gitter.im/apereo/cas
>>> - List Guidelines: https://goo.gl/1VRrw7
>>> - Contributions: https://goo.gl/mh7qDG
>>> ---
>>> You received this message because you are subscribed to the Google Groups 
>>> "CAS
>>> Community" group.
>>> To unsubscribe from this group and stop receiving emails from it, send an 
>>> email
>>> to [email protected] .
>>> To view this discussion on the web visit
>>> https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAN6MV5MpDqd-j04ykxuJ5Ae3iWz%2Bs53BLD0Wvd_ZWPAFvb1Bng%40mail.gmail.com
>>> .

>> --
>> --Misagh

>> --
>> - Website: https://apereo.github.io/cas
>> - Gitter Chatroom: https://gitter.im/apereo/cas
>> - List Guidelines: https://goo.gl/1VRrw7
>> - Contributions: https://goo.gl/mh7qDG
>> ---
>> You received this message because you are subscribed to the Google Groups 
>> "CAS
>> Community" group.
>> To unsubscribe from this group and stop receiving emails from it, send an 
>> email
>> to [email protected] .
>> To view this discussion on the web visit
>> https://groups.google.com/a/apereo.org/d/msgid/cas-user/1396343839.5711719.1508433250798.JavaMail.zimbra%40unicon.net
>> .

> --
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups "CAS
> Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email
> to [email protected] .
> To view this discussion on the web visit
> https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAN6MV5NpVr1XrsJ7LUBsBEeGXy3k1RHXqoEXXbkKuMEfjFCqyg%40mail.gmail.com
> .

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/892964821.9246869.1512522834850.JavaMail.zimbra%40unicon.net.

Reply via email to