Upgraded to 7.3.8: The same issue persists. 

On Thursday, July 16, 2026 at 11:32:19 AM UTC+10 Anthony Heng wrote:

> Hi,
>
> I am designing a system to following the RFC 8628 device authorization 
> flow, but the resulting access token ends up being linked to an anonymous 
> user rather than the openid profile for login. 
>
> I am using the endpoints at 
> https://apereo.github.io/cas/7.3.x/authentication/OAuth-ProtocolFlow-DeviceAuthorization.html
>  
> (this is equivalent to the previous 7.2.x docs) and I perform the following 
> steps:
>
> 1. Request a device code, user code, and verification uri from 
> /oauth2.0/accessToken, parameters including client_id=<CLIENT_ID>&
> response_type=device_code&scope=openid+profile+email+groups
> 2. The verification uri always leads to /oauth2.0/device, which I open in 
> a web browser, log in with my username/password. Leads to a page to enter 
> the user code which I do. 
> 3. loop to perform a GET request at  /oauth2.0/accessToken with the 
> previous parameters, in addition to the device_code until it returns a 
> successful 200 response with the access token. 
>
> I successfully obtain an access token, however this token is not linked to 
> the openid profile of the user who logged in at the verification uri. On 
> top of this, it seems like the scopes haven't been properly set either from 
> introspection/ oauth2 profile response:
>
> Introspection: 
> {'token': <access token>, 'active': True, 'sub': 'anonymous', 'scope': 
> 'CAS', 'iat': 1784160386, 'exp': 1784189186, 'uniqueSecurityName': 
> 'anonymous', 'tokenType': 'Bearer', 'aud': <client_id>, 'client_id': 
> <client_id>, 'grant_type': 'urn:ietf:params:oauth:grant-type:device_code', 
> 'cnf': {}}
>
> /oidc/oidcProfile :
> {'sub': 'anonymous', 'service': <service_id>, 'attributes': 
> {'authenticationDate': '2026-07-16T00:06:26.565966986Z', 'grant_type': 
> 'urn:ietf:params:oauth:grant-type:device_code', 'client_id': <client_id>}, 
> 'id': 'anonymous', 'client_id': <client_id>}
>
> For the relevant logs, it seems like the request isn't receiving my 
> required scopes either which I suspect is the case, but considering other 
> authentication flows work (e.g. legacy username/password) I'm not sure why.
>
> *After requesting device code:*
> WHAT: {code=N/A, grant_type=urn:ietf:params:oauth:grant-type:device_code, 
> service=<service_id>, scope=[]
> , response_type=device_code, redirect_uri=null, client_id=null} 
> ACTION: OAUTH2_ACCESS_TOKEN_REQUEST_CREATED 
> ...
>
> > 
> 2026-07-16 10:15:31,958 INFO [org.apereo.inspektr.audit.AuditTrailManager] 
> - <Audit trail record BEGIN 
> ============================================================= 
> WHEN: 2026-07-16T00:15:31.958294990 
> WHO: audit:unknown 
> WHAT: {user_code=<user code>, device_code=<device code>, interval=15, 
> verification_uri=https://cas.example.org/oauth2.0/device, expires_in=300} 
> ACTION: OAUTH2_ACCESS_TOKEN_RESPONSE_CREATED
>
>
>
> *After device code is entered:*
> WHAT: {code=N/A, grant_type=urn:ietf:params:oauth:grant-type:device_code, 
> service=<service id>, scope=[]
> , response_type=device_code, redirect_uri=null, client_id=null} 
> ACTION: OAUTH2_ACCESS_TOKEN_REQUEST_CREATED
> ...
>
> > 
> 2026-07-16 10:10:58,289 DEBUG 
> [org.apereo.cas.authentication.CoreAuthenticationUtils] - <Merged 
> attributes with the final result as [{grant_type=[urn:ietf:p
> arams:oauth:grant-type:device_code], scope=[], client_id=[<client_id>]}]> 
> 2026-07-16 10:10:58,291 INFO [org.apereo.inspektr.audit.AuditTrailManager] 
> - <Audit trail record BEGIN 
> ============================================================= 
> WHEN: 2026-07-16T00:10:58.291001580 
> WHO: audit:unknown 
> WHAT: {access_token=<access_token>, token_type=Bearer, expires_in=28800} 
> ACTION: OAUTH2_ACCESS_TOKEN_RESPONSE_CREATED
>
>
> So I am wondering: am I missing something from this flow in order to 
> properly establish the link? Or is this likely a misconfiguration and if so 
> what could it be and what class should I trace to determine what the 
> misconfiguration is?
>
> Kind Regards,
>
> Anthony Heng
>

-- 
- Website: https://apereo.github.io/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/1cbaf6dd-8483-40ea-92c3-0d57e577bc73n%40apereo.org.

Reply via email to