I've wrote a custom consent engine to solve this issue:
@Slf4j
@Getter
public class CustomConsentEngine extends DefaultConsentEngine {
private static final int MAP_SIZE = 8;
private final SamlIdPProperties samlIdPProperties;
private final AttributeDefinitionStore attributeDefinitionStore;
public CustomConsentEngine(ConsentRepository consentRepository,
ConsentDecisionBuilder consentDecisionBuilder, SamlIdPProperties
samlIdPProperties, AttributeDefinitionStore attributeDefinitionStore) {
super(consentRepository, consentDecisionBuilder);
this.samlIdPProperties = samlIdPProperties;
this.attributeDefinitionStore = attributeDefinitionStore;
}
@Override
public Map<String, List<Object>> resolveConsentableAttributesFrom(final
Authentication authentication,
final
Service service,
final
RegisteredService registeredService) {
LOGGER.debug("Retrieving consentable attributes for [{}]",
registeredService);
val policy = registeredService.getAttributeReleasePolicy();
if (policy != null) {
Map<String, List<Object>> attributes =
policy.getConsentableAttributes(authentication.getPrincipal(), service,
registeredService);
// get friendly names if registeredService is instance of
SamlRegisteredService
if (registeredService instanceof SamlRegisteredService) {
val friendlyAttributes = new HashMap<String,
List<Object>>();
val samlRegisteredService = (SamlRegisteredService)
registeredService;
val globalFriendlyNames =
samlIdPProperties.getAttributeFriendlyNames();
val friendlyNames = new HashMap<String,
String>(CollectionUtils.convertDirectedListToMap(globalFriendlyNames));
attributeDefinitionStore.getAttributeDefinitions()
.stream()
.filter(defn -> defn instanceof
SamlIdPAttributeDefinition)
.map(SamlIdPAttributeDefinition.class::cast)
.filter(defn ->
StringUtils.isNotBlank(defn.getFriendlyName()))
.forEach(defn -> friendlyNames.put(defn.getKey(),
defn.getFriendlyName()));
friendlyNames.putAll(samlRegisteredService.getAttributeFriendlyNames());
for (val e : attributes.entrySet()) {
if (e.getValue() instanceof Collection<?> &&
((Collection<?>) e.getValue()).isEmpty()) {
LOGGER.info("Skipping attribute [{}] because it
does not have any values.", e.getKey());
continue;
}
val friendlyName =
friendlyNames.getOrDefault(e.getKey(), e.getKey());
friendlyAttributes.put(friendlyName, e.getValue());
}
return friendlyAttributes;
}
return attributes;
}
return new LinkedHashMap<>(MAP_SIZE);
}
}
--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/4507700a-10aa-453a-98cf-747563997d63%40apereo.org.