Misagh,

Do you have any other examples of the custom triggers? I have written a
custom trigger but am getting a NullPointerException as follows:

2017-12-07 10:36:53,826 [https-jsse-nio-8444-exec-1] WARN
org.apereo.cas.web.flow.resolver.impl.InitialAuthenticationAttemptWebflowEventResolver
- null

java.lang.NullPointerException: null

at edu.vcu.cas.duo.web.CustomWebFlowEventResolver.resolveInternal(
CustomWebFlowEventResolver.java:53) ~[classes!/:5.1.4]

at
org.apereo.cas.web.flow.resolver.impl.AbstractCasWebflowEventResolver.resolve(
AbstractCasWebflowEventResolver.java:475)
~[cas-server-core-webflow-5.1.4.jar!/:5.1.4]

at
org.apereo.cas.web.flow.resolver.impl.AbstractCasWebflowEventResolver.resolveSingle(
AbstractCasWebflowEventResolver.java:480)
~[cas-server-core-webflow-5.1.4.jar!/:5.1.4]

...


This is the configuration class


@Configuration("customWebFlowEventResolverConfiguration")

@EnableConfigurationProperties(CasConfigurationProperties.class)

public class CustomWebFlowEventResolverConfiguration {


@Autowired

@Qualifier("initialAuthenticationAttemptWebflowEventResolver")

private CasDelegatingWebflowEventResolver initialEventResolver;


@Autowired

@Qualifier("centralAuthenticationService")

private CentralAuthenticationService centralAuthenticationService;


@Autowired

@Qualifier("defaultAuthenticationSystemSupport")

private AuthenticationSystemSupport authenticationSystemSupport;


@Autowired

@Qualifier("defaultTicketRegistrySupport")

private TicketRegistrySupport ticketRegistrySupport;


@Autowired

@Qualifier("servicesManager")

private ServicesManager servicesManager;


@Autowired(required = false)

@Qualifier("multifactorAuthenticationProviderSelector")

private MultifactorAuthenticationProviderSelector
multifactorAuthenticationProviderSelector = new
RankedMultifactorAuthenticationProviderSelector();


@Autowired

@Qualifier("warnCookieGenerator")

private CookieGenerator warnCookieGenerator;


@Autowired

@Qualifier("authenticationServiceSelectionPlan")

private AuthenticationServiceSelectionPlan
authenticationRequestServiceSelectionStrategies;


@RefreshScope

@Bean

public CasWebflowEventResolver customWebflowEventResolver() {

return new CustomWebFlowEventResolver(authenticationSystemSupport,
centralAuthenticationService,

servicesManager, ticketRegistrySupport, warnCookieGenerator,

authenticationRequestServiceSelectionStrategies,
multifactorAuthenticationProviderSelector);

}


@PostConstruct

public void initialize() {

initialEventResolver.addDelegate(customWebflowEventResolver());

}


}

This is the WebflowEventResolver:


public class CustomWebFlowEventResolver extends
AbstractCasWebflowEventResolver {


public CustomWebFlowEventResolver(AuthenticationSystemSupport
authenticationSystemSupport,

CentralAuthenticationService centralAuthenticationService, ServicesManager
servicesManager,

TicketRegistrySupport ticketRegistrySupport, CookieGenerator
warnCookieGenerator,

AuthenticationServiceSelectionPlan authenticationSelectionStrategies,

MultifactorAuthenticationProviderSelector selector) {

super(authenticationSystemSupport, centralAuthenticationService,
servicesManager, ticketRegistrySupport,

warnCookieGenerator, authenticationSelectionStrategies, selector);

}


@Override

public Set<Event> resolveInternal(RequestContext context) {

final RegisteredService service = WebUtils.getRegisteredService(context);

final Authentication authentication = WebUtils.getAuthentication(context);


final Map<String, MultifactorAuthenticationProvider> providerMap = WebUtils

.getAvailableMultifactorAuthenticationProviders(applicationContext);

final MultifactorAuthenticationProvider provider = providerMap.get("mfa-duo"
);

final Map eventAttributes =
buildEventAttributeMap(authentication.getPrincipal(),
service,

provider);

final Event event =
validateEventIdForMatchingTransitionInContext(provider.getId(),
context, eventAttributes);

return ImmutableSet.of(event);

}


}



I have registered the Configuration in the META-INF/spring.factories
configuration file.


Thanks,
Adam


On Tue, Dec 5, 2017 at 8:13 PM, Misagh Moayyed <[email protected]> wrote:

> Caching can be controlled but it’s today based on a per-app basis:
> https://apereo.github.io/cas/5.2.x/integration/Attribute-
> Release-Caching.html
>
> Also, it might better to review this page for options that handle bypass
> more dynamically:
> https://apereo.github.io/cas/5.2.x/installation/Configuring-Multifactor-
> Authentication-Bypass.html
>
> …which should get invoked every time.
>
> --Misagh
>
> ------------------------------
>
> *From: *"Adam Causey" <[email protected]>
> *To: *[email protected]
> *Sent: *Tuesday, December 5, 2017 1:39:54 PM
>
> *Subject: *Re: [cas-user] Customized MFA bypass in CAS 5.1.x
>
> Is there a way to not cache the attributes that are retrieved via a Groovy
> script?  I noticed they are cached, and I need the bypass check to occur on
> every login, including the SSO logins.
>
> Thanks,
> Adam
>
> On Thu, Oct 19, 2017 at 1:14 PM, Misagh Moayyed <[email protected]>
> wrote:
>
>> Sorry; too many versions to keep track of. I was of thinking of 5.2 where
>> you can hit a rest endpoint and have it return attributes for you. No such
>> thing in 5.1. My bad. Alternatively, you write a groovy script that would
>> do the same.
>> https://apereo.github.io/cas/5.1.x/installation/
>> Configuration-Properties.html#groovy
>>
>> ------------------------------
>>
>> *From: *"Adam Causey" <[email protected]>
>> *To: *[email protected]
>> *Sent: *Thursday, October 19, 2017 9:59:05 AM
>> *Subject: *Re: [cas-user] Customized MFA bypass in CAS 5.1.x
>>
>> How and where would I populate the Principal? Are there any examples you
>> could provide.
>>
>> Thanks,
>> Adam
>>
>> On Thu, Oct 19, 2017 at 12:46 PM, Misagh Moayyed <[email protected]>
>> wrote:
>>
>>> Not unless you write your own trigger. One other option would be to make
>>> the REST call and populate the principal with an attribute that says
>>> "bypass=true". Then let the bypass logic use that attribute. Likely more
>>> performant.
>>>
>>> ------------------------------
>>>
>>> *From: *"Adam Causey" <[email protected]>
>>> *To: *[email protected]
>>> *Sent: *Thursday, October 19, 2017 8:52:20 AM
>>> *Subject: *[cas-user] Customized MFA bypass in CAS 5.1.x
>>>
>>> Is there a way to add our own custom bypass logic to CAS 5.1.x?
>>> Specifically I would like to make a call to a RESTful API that returns a
>>> boolean value that says whether the user can bypass or not.
>>>
>>> Thanks,
>>> Adam
>>>
>>> --
>>> - Website: https://apereo.github.io/cas
>>> - Gitter Chatroom: https://gitter.im/apereo/cas
>>> - List Guidelines: https://goo.gl/1VRrw7
>>> - Contributions: https://goo.gl/mh7qDG
>>> ---
>>> You received this message because you are subscribed to the Google
>>> Groups "CAS Community" group.
>>> To unsubscribe from this group and stop receiving emails from it, send
>>> an email to [email protected].
>>> To view this discussion on the web visit https://groups.google.com/a/
>>> apereo.org/d/msgid/cas-user/CAN6MV5ON1ibwsupJjYCJ2cnF3MA4O
>>> XnzoqH%2B29pwiP8OLY%2BX2Q%40mail.gmail.com
>>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAN6MV5ON1ibwsupJjYCJ2cnF3MA4OXnzoqH%2B29pwiP8OLY%2BX2Q%40mail.gmail.com?utm_medium=email&utm_source=footer>
>>> .
>>>
>>>
>>> --
>>> --Misagh
>>>
>>> --
>>> - Website: https://apereo.github.io/cas
>>> - Gitter Chatroom: https://gitter.im/apereo/cas
>>> - List Guidelines: https://goo.gl/1VRrw7
>>> - Contributions: https://goo.gl/mh7qDG
>>> ---
>>> You received this message because you are subscribed to the Google
>>> Groups "CAS Community" group.
>>> To unsubscribe from this group and stop receiving emails from it, send
>>> an email to [email protected].
>>> To view this discussion on the web visit https://groups.google.com/a/
>>> apereo.org/d/msgid/cas-user/1598432640.5707319.
>>> 1508431562461.JavaMail.zimbra%40unicon.net
>>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/1598432640.5707319.1508431562461.JavaMail.zimbra%40unicon.net?utm_medium=email&utm_source=footer>
>>> .
>>>
>>
>> --
>> - Website: https://apereo.github.io/cas
>> - Gitter Chatroom: https://gitter.im/apereo/cas
>> - List Guidelines: https://goo.gl/1VRrw7
>> - Contributions: https://goo.gl/mh7qDG
>> ---
>> You received this message because you are subscribed to the Google Groups
>> "CAS Community" group.
>> To unsubscribe from this group and stop receiving emails from it, send an
>> email to [email protected].
>> To view this discussion on the web visit https://groups.google.com/a/
>> apereo.org/d/msgid/cas-user/CAN6MV5MpDqd-j04ykxuJ5Ae3iWz%
>> 2Bs53BLD0Wvd_ZWPAFvb1Bng%40mail.gmail.com
>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAN6MV5MpDqd-j04ykxuJ5Ae3iWz%2Bs53BLD0Wvd_ZWPAFvb1Bng%40mail.gmail.com?utm_medium=email&utm_source=footer>
>> .
>>
>>
>> --
>> --Misagh
>>
>> --
>> - Website: https://apereo.github.io/cas
>> - Gitter Chatroom: https://gitter.im/apereo/cas
>> - List Guidelines: https://goo.gl/1VRrw7
>> - Contributions: https://goo.gl/mh7qDG
>> ---
>> You received this message because you are subscribed to the Google Groups
>> "CAS Community" group.
>> To unsubscribe from this group and stop receiving emails from it, send an
>> email to [email protected].
>> To view this discussion on the web visit https://groups.google.com/a/
>> apereo.org/d/msgid/cas-user/1396343839.5711719.
>> 1508433250798.JavaMail.zimbra%40unicon.net
>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/1396343839.5711719.1508433250798.JavaMail.zimbra%40unicon.net?utm_medium=email&utm_source=footer>
>> .
>>
>
> --
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit https://groups.google.com/a/
> apereo.org/d/msgid/cas-user/CAN6MV5NpVr1XrsJ7LUBsBEeGXy3k1
> RHXqoEXXbkKuMEfjFCqyg%40mail.gmail.com
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAN6MV5NpVr1XrsJ7LUBsBEeGXy3k1RHXqoEXXbkKuMEfjFCqyg%40mail.gmail.com?utm_medium=email&utm_source=footer>
> .
>
> --
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit https://groups.google.com/a/
> apereo.org/d/msgid/cas-user/892964821.9246869.
> 1512522834850.JavaMail.zimbra%40unicon.net
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/892964821.9246869.1512522834850.JavaMail.zimbra%40unicon.net?utm_medium=email&utm_source=footer>
> .
>

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAN6MV5M7sWx7m1JVVyx933wT3Hhb4YSXFAO5Ask7Gn%3Diimk2ZQ%40mail.gmail.com.

Reply via email to