I found a lead. I used the blog post 
https://fawnoos.com/2022/08/18/cas66-openid-connect-scopes/ to customize my 
OpenLDAP attributes as follows in the cas.properties file :

cas.authn.oidc.core.claims-map.email=mailRoutingAddress
cas.authn.oidc.core.claims-map.MemberOf=crnpdcattgroupe
cas.authn.oidc.core.claims-map.firstname=givenName
cas.authn.oidc.core.claims-map.lastname=sn
cas.authn.oidc.core.claims-map.displayname=displayName
cas.authn.oidc.core.claims-map.compteactif=crnpdcattcompteactif
cas.authn.oidc.core.claims-map.fonction=crnpdcattfonctionlibelle
cas.authn.oidc.core.claims-map.secteur=crnpdcattsecteurlibelle
cas.authn.oidc.core.claims-map.service=crnpdcattservicelibelle
as.authn.oidc.core.claims-map.departement=crnpdcattdepartementlibelle
cas.authn.oidc.core.claims-map.direction=crnpdcattdirectionlibelle
cas.authn.oidc.core.claims-map.contrat=employeeType
cas.authn.oidc.core.user-defined-scopes.organisation=fonction,service,departement,direction
cas.authn.oidc.core.user-defined-scopes.openid=sub
cas.authn.oidc.core.user-defined-scopes.profile=uid,firstname,lastname,displayname,compteactif,contrat
cas.authn.oidc.core.user-defined-scopes.MemberOf=MemberOf
cas.authn.oidc.core.user-defined-scopes.ismemberof=MemberOf
cas.authn.oidc.core.user-defined-scopes.memberofargos=MemberOf
cas.authn.oidc.core.user-defined-scopes.memberofedgar=MemberOf
cas.authn.oidc.core.user-defined-scopes.memberofsigport=MemberOf
cas.authn.oidc.discovery.claims=sub,uid,email,firstname,lastname,displayname,compteactif,fonction,secteur,service,departement,direction,contrat,MemberOf,ismemberof,memberofargos,memberofedgar,memberofsigport
cas.authn.oidc.discovery.scopes=sub,openid,profile,email,organisation,MemberOf,memberofargos,memberofedgar,memberofsigport,ismemberof

and my json service :

{
    "@class": "org.apereo.cas.services.OidcRegisteredService",
    "serviceId": "https://....../iam/realms/SP/broker/oidc-hdf/endpoint";,
    "name": "SP-v09",
    "id": 329738878,
    "description": "OpenID Connect service SP-v09",
    "attributeReleasePolicy": {
        "@class": "org.apereo.cas.services.ChainingAttributeReleasePolicy",
        "policies": [
            "java.util.ArrayList",
            [
                {
                    "@class": 
"org.apereo.cas.oidc.claims.OidcProfileScopeAttributeReleasePolicy"
                },
                {
                    "@class": 
"org.apereo.cas.oidc.claims.OidcEmailScopeAttributeReleasePolicy"
                }
            ]
        ],
        "mergingPolicy": "REPLACE",
        "principalAttributesRepository": {
            "@class": 
"org.apereo.cas.authentication.principal.ChainingPrincipalAttributesRepository"
        },
        "consentPolicy": {
            "@class": 
"org.apereo.cas.services.consent.ChainingRegisteredServiceConsentPolicy"
        },
        "authorizedToReleaseAuthenticationAttributes": true
    },
    "clientSecret": "xxxxxxxxxxx",
    "clientId": "xxxxxxxxxxxxxxxxx",
    "bypassApprovalPrompt": true,
    "jwtAccessToken": true,
    "supportedGrantTypes": [
        "java.util.HashSet",
        [
            "refresh_token",
            "client_credentials",
            "authorization_code"
        ]
    ],
    "supportedResponseTypes": [
        "java.util.HashSet",
        [
            "code",
            "id_token"
        ]
    ],
    "scopes": [
        "java.util.HashSet",
        [
            "openid",
            "profile",
            "email"
        ]
    ]
}

It seems the attributes are being lost because if I don't customize the 
OpenLDAP attributes, I find them correctly in the id_toekn.

    "attributeReleasePolicy": {
        "@class": 
"org.apereo.cas.services.ReturnAllowedAttributeReleasePolicy",
        "allowedAttributes": [
            "java.util.ArrayList",
            [
                "uid",
                "givenName",
                "mailRoutingAddress",
                "sn",
                "crnpdcattgroupe"
            ]
        ]
    },

How to use attributes friendly name in json service and configured in 
cas.properties file ?

Thanks
Le mercredi 27 mai 2026 à 15:43:58 UTC+2, livio dezorzi a écrit :

> Hello,
> I'm having a problem with CAS v7.3.6 and a Service Provider using Keycloak 
> and OpenID Connect. I need to publish the attributes in `id_token`. In my 
> JSON service, I declared `supportedResponseTypes` with `code` and 
> `id_token`. But when I log into the application, after decoding the 
> `id_token`, I can't find the attributes like firtname, lastname, email...
> However, with a php/apache2 test application and 
> libapache2-mod-auth-openidc which retrieves the attributes in the header, I 
> have all my attributes published.
> The JSON services are identical except for the client and secret ID. Where 
> did I go wrong ? 
> Just so you know, my .well-known/openid-configuration file clearly 
> specifies the supported response types: code, id_token, id_token token, and 
> device_code
> Thanks for your leads 
>

-- 
- Website: https://apereo.github.io/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/48758c01-21b6-4584-b94f-b8403cc92368n%40apereo.org.

Reply via email to