Thanks for your configuration file.
I notice that the “openid” and “profile” scopes aren't returning any
attributes.
In my application-side logs, only the email address is being logged.
Do I need to declare something?
Le dimanche 19 juillet 2026 à 22:18:00 UTC+2, Ray Bon a écrit :
> Vallee,
>
> Not all of the properties in the service are required.
> There are also some custom scopes.
>
> Ray
>
> {
> "@class": "org.apereo.cas.services.OidcRegisteredService",
> "serviceId": "^
> https://democasclientlocal.uvic.ca/democasclient/callback.*[oO]idc.*",
> "name": "Demo-OIDC",
> "id": 10002,
> "proxyTicketExpirationPolicy":
> {
> "@class":
> "org.apereo.cas.services.DefaultRegisteredServiceProxyTicketExpirationPolicy"
> },
> "serviceTicketExpirationPolicy":
> {
> "@class":
> "org.apereo.cas.services.DefaultRegisteredServiceServiceTicketExpirationPolicy"
> },
> "singleSignOnParticipationPolicy": {
> "@class":
> "org.apereo.cas.services.ChainingRegisteredServiceSingleSignOnParticipationPolicy"
> },
> "evaluationOrder": 145,
> "usernameAttributeProvider": {
> "@class":
> "org.apereo.cas.services.DefaultRegisteredServiceUsernameProvider",
> "canonicalizationMode": "LOWER"
> },
> "environments": null,
> "multifactorPolicy": {
> "@class":
> "org.apereo.cas.services.DefaultRegisteredServiceMultifactorPolicy",
> "multifactorAuthenticationProviders": null,
> "bypassEnabled": true
> },
> "attributeReleasePolicy":
> {
> "@class": "org.apereo.cas.services.DenyAllAttributeReleasePolicy"
> },
> "clientSecret": "secret",
> "clientId": "demoId",
> "bypassApprovalPrompt": false,
> "generateRefreshToken": true,
> "jwtAccessToken": true,
> "supportedGrantTypes":
> [
> "java.util.HashSet",
> [
> "refresh_token",
> "password",
> "authorization_code"
> ]
> ],
> "supportedResponseTypes":
> [
> "java.util.HashSet",
> [
> "code",
> "id_token",
> "token"
> ]
> ],
> "signIdToken": false,
> "subjectType": "PUBLIC",
> "scopes": [
> "java.util.HashSet", [
> "uvicApplications",
> "openid",
> "email",
> "profile",
> "eduPerson"
> ]
> ]
> }
>
> ------------------------------
> *From:* [email protected] <[email protected]> on behalf of Vallee
> Romain <[email protected]>
> *Sent:* July 18, 2026 01:47
> *To:* CAS Community <[email protected]>
> *Cc:* Vallee Romain <[email protected]>
> *Subject:* [cas-user] Re: OIDC with 7.3 and code
>
> You don't often get email from [email protected]. Learn why this is
> important <https://aka.ms/LearnAboutSenderIdentification>
> Thank to @JeromeLeleu .
>
> Just add this :
>
> cas.authn.oauth.session-replication.cookie.crypto.enabled=true
>
> Now, i have to find how create à json service file to bring attributs to
> application.
>
> Could someone provide me with an example of a JSON file that would work
> with OIDC? One that sends attributes?
>
>
>
> Le vendredi 17 juillet 2026 à 13:32:33 UTC+2, Vallee Romain a écrit :
>
> Hello,
>
> I migrated from version 6 to latest version 7 of Jasig, and since then, my
> services that use OIDC authentication no longer work. We're getting this
> error message:
>
> Argument #2 ($code) must be of type string, null given, called in .
>
> I tried adapting my services using this syntax:
>
> root@cas7:/etc/cas/config# cat ../services/centreon-16.json
>
>
> {
>
> “@class”: “org.apereo.cas.services.OidcRegisteredService”,
>
> “clientId”: “xxxxx”,
>
> “clientSecret”: “xxxxx”,
>
> “serviceId”: “
> http://192.168.14.159/centreon/authentication/providers/configurations/openid
> ”,
>
> “evaluationOrder”: 1,
>
> “name”: “centreon”,
>
> “id”: 16,
>
> “bypassApprovalPrompt”: true,
>
> “accessStrategy”: {
>
> “@class”: “org.apereo.cas.services.DefaultRegisteredServiceAccessStrategy”,
>
> “enabled”: true,
>
> “ssoEnabled”: true,
>
> “requireAllAttributes”: false,
>
> “requiredAttributes”: {
>
> “@class”: “java.util.HashMap”
>
> },
>
> “caseInsensitive”: false
>
> },
>
> “userProfileViewType”: “FLAT”,
>
> “supportedGrantTypes”: [“java.util.HashSet”, [“authorization_code”]],
>
> “supportedResponseTypes”: [“java.util.HashSet”, [“code”]],
>
> “scopes”: [“java.util.HashSet”,
> [“openid”,“profile”,“email”,‘groups’,“roles”]],
>
> “includeClaimsInIdToken”: true
>
> }
>
>
> The logs don't show anything unusual.
>
>
> Have you ever encountered this problem?
>
>
> Thank you
>
> Best regards
>
> --
> - Website: https://apereo.github.io/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion visit
> https://groups.google.com/a/apereo.org/d/msgid/cas-user/c45ceb63-1a05-4e22-a608-8e62519fc514n%40apereo.org
>
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/c45ceb63-1a05-4e22-a608-8e62519fc514n%40apereo.org?utm_medium=email&utm_source=footer>
> .
>
--
- Website: https://apereo.github.io/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/0cd2b8b2-fd60-41cc-bc2c-009399b7e310n%40apereo.org.