Hi Les,

I was preparing a demo on CAS support for Shiro :
https://github.com/leleuj/cas-shiro-demo and I did realize the remember-me
feature is not fully addressed.

One use case is missing : if the user is already remembered (by CAS) and
want to be authenticated, it should be redirected to CAS server with a
specific parameter (renew=true) to force CAS re-authentication.
For this use case, I created a CasAuthenticatedUserFilter which checks if
the user is authenticated (not remembered) and sends him to the CAS server
if he's not (with the specific parameter to force re-authentication if he's
already remembered).

I created a JIRA SHIRO-373 and attached the SVN patch.

I'm waiting for your feedback.

Thanks.
Best regards,
Jérôme


--
View this message in context: 
http://shiro-developer.582600.n2.nabble.com/Complete-CAS-remember-me-support-tp7577498.html
Sent from the Shiro Developer mailing list archive at Nabble.com.

Reply via email to