First attempt on mapping attributes is done via getConsentableAttributes() in AbstractRegisteredServiceAttributeReleasePolicy.class. Second attempt is done via ensurePrincipalAccessIsAllowedForService() in RegisteredServiceAccessStrategyUtils.
Am Montag, 9. März 2020 13:26:22 UTC+1 schrieb Robert Kornmesser: > > I'm just testing attribute lookup via persondirectory and have a simple > service allowing to return mapped attributes. > Everything seems to work. The attributes are getting mapped and consent > screen is showing the renamed attributes with their value. > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,026 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping > attribute [acceptedCurrentTermsOfUse] to [acceptedCurrentTermsOfUse] with > value [[1]]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,027 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found > attribute [acceptedCurrentTermsOfUse] in the list of allowed attributes, > mapped to the name [acceptedCurrentTermsOfUse]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,028 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping > attribute [gfzIdmPersonId] to [gfzIdmPersonId] with value [[XXX]]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,028 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found > attribute [gfzIdmPersonId] in the list of allowed attributes, mapped to > the name [gfzIdmPersonId]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,028 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping > attribute [gfzIdmPersonId] to [personId] with value [[XXX]]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,029 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found > attribute [gfzIdmPersonId] in the list of allowed attributes, mapped to > the name [personId]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,029 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping > attribute [gfzRole] to [roles] with value [[uberadmin, user, XXX, XXX, XXX > ]]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,029 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found > attribute [gfzRole] in the list of allowed attributes, mapped to the name > [roles]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,030 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping > attribute [gfzSection] to [section] with value [[XXX]]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,030 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found > attribute [gfzSection] in the list of allowed attributes, mapped to the > name [section]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,030 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping > attribute [title] to [title] with value [[XXX]]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,030 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found > attribute [title] in the list of allowed attributes, mapped to the name [ > title]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,031 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping > attribute [uid] to [username] with value [[XXX]]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,032 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found > attribute [uid] in the list of allowed attributes, mapped to the name [ > username]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,032 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping > attribute [urn:oid:0.9.2342.19200300.100.1.3] to [email] with value [[XXX > ]]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,032 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found > attribute [urn:oid:0.9.2342.19200300.100.1.3] in the list of allowed > attributes, mapped to the name [email]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,032 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping > attribute [urn:oid:2.16.840.1.113730.3.1.241] to [fullname] with value [[XXX > XXX]]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,033 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found > attribute [urn:oid:2.16.840.1.113730.3.1.241] in the list of allowed > attributes, mapped to the name [fullname]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,033 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping > attribute [urn:oid:2.5.4.4] to [lastname] with value [[XXX]]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,033 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found > attribute [urn:oid:2.5.4.4] in the list of allowed attributes, mapped to > the name [lastname]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,033 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping > attribute [urn:oid:2.5.4.42] to [firstname] with value [[XXX]]> > > Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,034 DEBUG [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found > attribute [urn:oid:2.5.4.42] in the list of allowed attributes, mapped to > the name [firstname]> > > > > But, after the oauth approval prompt is accepted (which comes next), > the ReturnMappedAttributeReleasePolicy is called for a second time and CAS > tries to map my attributes again, which results in: > > Mar 09 13:07:50 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:50,354 WARN [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not > find value for mapped attribute [roles] that is based off of [gfzRole] in > the allowed attribu > tes list. Ensure the original attribute [gfzRole] is retrieved and > contains at least a single value. Attribute [roles] will and can not be > released without the presence of a value.> > > Mar 09 13:07:50 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:50,737 WARN [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not > find value for mapped attribute [section] that is based off of [gfzSection > ] in the allowed at > tributes list. Ensure the original attribute [gfzSection] is retrieved and > contains at least a single value. Attribute [section] will and can not be > released without the presence of a value.> > > Mar 09 13:07:52 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:50,967 WARN [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not > find value for mapped attribute [username] that is based off of [uid] in > the allowed attribut > es list. Ensure the original attribute [uid] is retrieved and contains at > least a single value. Attribute [username] will and can not be released > without the presence of a value.> > > Mar 09 13:07:52 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:51,182 WARN [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not > find value for mapped attribute [email] that is based off of [urn:oid:0.9. > 2342.19200300.100.1 > .3] in the allowed attributes list. Ensure the original attribute [urn:oid > :0.9.2342.19200300.100.1.3] is retrieved and contains at least a single > value. Attribute [email] will and can not be released without the > presence of a value.> > > Mar 09 13:07:52 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:51,425 WARN [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not > find value for mapped attribute [fullname] that is based off of [urn:oid: > 2.16.840.1.113730.3. > 1.241] in the allowed attributes list. Ensure the original attribute [urn: > oid:2.16.840.1.113730.3.1.241] is retrieved and contains at least a > single value. Attribute [fullname] will and can not be released without > the presence of a value. > > > > Mar 09 13:07:52 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:51,654 WARN [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not > find value for mapped attribute [lastname] that is based off of [urn:oid: > 2.5.4.4] in the allo > wed attributes list. Ensure the original attribute [urn:oid:2.5.4.4] is > retrieved and contains at least a single value. Attribute [lastname] will > and can not be released without the presence of a value.> > > Mar 09 13:07:52 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:52,029 WARN [ > org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not > find value for mapped attribute [firstname] that is based off of [urn:oid: > 2.5.4.42] in the al > lowed attributes list. Ensure the original attribute [urn:oid:2.5.4.42] is > retrieved and contains at least a single value. Attribute [firstname] > will and can not be released without the presence of a value.> > > > *Why is CAS trying to map the already mapped attributes again?* > -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/92ead470-4180-45aa-bc07-b59649054edb%40apereo.org.
