First attempt on mapping attributes is done via getConsentableAttributes() 
in AbstractRegisteredServiceAttributeReleasePolicy.class.
Second attempt is done via ensurePrincipalAccessIsAllowedForService() 
in RegisteredServiceAccessStrategyUtils.

Am Montag, 9. März 2020 13:26:22 UTC+1 schrieb Robert Kornmesser:
>
> I'm just testing attribute lookup via persondirectory and have a simple 
> service allowing to return mapped attributes.
> Everything seems to work. The attributes are getting mapped and consent 
> screen is showing the renamed attributes with their value.
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,026 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping 
> attribute [acceptedCurrentTermsOfUse] to [acceptedCurrentTermsOfUse] with 
> value [[1]]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,027 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found 
> attribute [acceptedCurrentTermsOfUse] in the list of allowed attributes, 
> mapped to the name [acceptedCurrentTermsOfUse]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,028 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping 
> attribute [gfzIdmPersonId] to [gfzIdmPersonId] with value [[XXX]]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,028 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found 
> attribute [gfzIdmPersonId] in the list of allowed attributes, mapped to 
> the name [gfzIdmPersonId]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,028 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping 
> attribute [gfzIdmPersonId] to [personId] with value [[XXX]]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,029 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found 
> attribute [gfzIdmPersonId] in the list of allowed attributes, mapped to 
> the name [personId]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,029 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping 
> attribute [gfzRole] to [roles] with value [[uberadmin, user, XXX, XXX, XXX
> ]]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,029 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found 
> attribute [gfzRole] in the list of allowed attributes, mapped to the name 
> [roles]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,030 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping 
> attribute [gfzSection] to [section] with value [[XXX]]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,030 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found 
> attribute [gfzSection] in the list of allowed attributes, mapped to the 
> name [section]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,030 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping 
> attribute [title] to [title] with value [[XXX]]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,030 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found 
> attribute [title] in the list of allowed attributes, mapped to the name [
> title]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,031 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping 
> attribute [uid] to [username] with value [[XXX]]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,032 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found 
> attribute [uid] in the list of allowed attributes, mapped to the name [
> username]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,032 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping 
> attribute [urn:oid:0.9.2342.19200300.100.1.3] to [email] with value [[XXX
> ]]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,032 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found 
> attribute [urn:oid:0.9.2342.19200300.100.1.3] in the list of allowed 
> attributes, mapped to the name [email]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,032 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping 
> attribute [urn:oid:2.16.840.1.113730.3.1.241] to [fullname] with value [[XXX 
> XXX]]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,033 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found 
> attribute [urn:oid:2.16.840.1.113730.3.1.241] in the list of allowed 
> attributes, mapped to the name [fullname]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,033 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping 
> attribute [urn:oid:2.5.4.4] to [lastname] with value [[XXX]]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,033 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found 
> attribute [urn:oid:2.5.4.4] in the list of allowed attributes, mapped to 
> the name [lastname]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,033 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Mapping 
> attribute [urn:oid:2.5.4.42] to [firstname] with value [[XXX]]>
>
> Mar 09 13:18:39 rz-dev-21 cas.war[18569]: 2020-03-09 13:18:39,034 DEBUG [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Found 
> attribute [urn:oid:2.5.4.42] in the list of allowed attributes, mapped to 
> the name [firstname]>
>
>
>
> But, after the oauth approval prompt is accepted (which comes next), 
> the ReturnMappedAttributeReleasePolicy is called for a second time and CAS 
> tries to map my attributes again, which results in:
>
> Mar 09 13:07:50 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:50,354 WARN [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not 
> find value for mapped attribute [roles] that is based off of [gfzRole] in 
> the allowed attribu
> tes list. Ensure the original attribute [gfzRole] is retrieved and 
> contains at least a single value. Attribute [roles] will and can not be 
> released without the presence of a value.>
>
> Mar 09 13:07:50 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:50,737 WARN [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not 
> find value for mapped attribute [section] that is based off of [gfzSection
> ] in the allowed at
> tributes list. Ensure the original attribute [gfzSection] is retrieved and 
> contains at least a single value. Attribute [section] will and can not be 
> released without the presence of a value.>
>
> Mar 09 13:07:52 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:50,967 WARN [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not 
> find value for mapped attribute [username] that is based off of [uid] in 
> the allowed attribut
> es list. Ensure the original attribute [uid] is retrieved and contains at 
> least a single value. Attribute [username] will and can not be released 
> without the presence of a value.>
>
> Mar 09 13:07:52 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:51,182 WARN [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not 
> find value for mapped attribute [email] that is based off of [urn:oid:0.9.
> 2342.19200300.100.1
> .3] in the allowed attributes list. Ensure the original attribute [urn:oid
> :0.9.2342.19200300.100.1.3] is retrieved and contains at least a single 
> value. Attribute [email] will and can not be released without the 
> presence of a value.>
>
> Mar 09 13:07:52 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:51,425 WARN [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not 
> find value for mapped attribute [fullname] that is based off of [urn:oid:
> 2.16.840.1.113730.3.
> 1.241] in the allowed attributes list. Ensure the original attribute [urn:
> oid:2.16.840.1.113730.3.1.241] is retrieved and contains at least a 
> single value. Attribute [fullname] will and can not be released without 
> the presence of a value.
> >
>
> Mar 09 13:07:52 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:51,654 WARN [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not 
> find value for mapped attribute [lastname] that is based off of [urn:oid:
> 2.5.4.4] in the allo
> wed attributes list. Ensure the original attribute [urn:oid:2.5.4.4] is 
> retrieved and contains at least a single value. Attribute [lastname] will 
> and can not be released without the presence of a value.>
>
> Mar 09 13:07:52 rz-dev-21 cas.war[18091]: 2020-03-09 13:07:52,029 WARN [
> org.apereo.cas.services.ReturnMappedAttributeReleasePolicy] - <Could not 
> find value for mapped attribute [firstname] that is based off of [urn:oid:
> 2.5.4.42] in the al
> lowed attributes list. Ensure the original attribute [urn:oid:2.5.4.42] is 
> retrieved and contains at least a single value. Attribute [firstname] 
> will and can not be released without the presence of a value.>
>
>
> *Why is CAS trying to map the already mapped attributes again?*
>

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/92ead470-4180-45aa-bc07-b59649054edb%40apereo.org.

Reply via email to