1. Only the Spring Boot security endpoints trigger authentication, but the classic CAS status pages (e.g. /cas/status/dashboard) do not. This means there is no way to access them, unless you disable Spring Security and use cas.adminPagesSecurity again.
You’ll need to map the endpoints in the settings to catch /cas/status/**. 2. The Spring Boot security endpoints also don't work, because they are not configured to supply information. See above. 3. It would be nice if you could select CAS authentication instead of basic authentication in Spring Security. Already possible. See settings. 4. LdapAutenticationProvider validates roles based on cas.adminPagesSecurity.adminRoles instead of management.security.roles (is this wrong or does it just need documentation?). Probably a bug. 5. LdapUserAttributesToRolesAuthorizationGenerator always does a user search and ignores cas.adminPagesSecurity.ldap.type. Does it really need to fetch the user attributes again when LdapAuthenticationProvider.authenticate just did that? Don’t think it needs the type there. Type is only used for authN. 6. LdapUserGroupsToRolesAuthorizationGenerator throws an IllegalStateException when roleAttribute is not defined (our LDAP doesn't have a roleAttribute, only a groupAttribute). Note: CasWebApplicationSecurityConfiguration also checks the roleAttribute! You’d want to configure it such that the roles are ignored via the other generator. Activate the one that deals with groups only. 7. Our baseDn for groups is different from the one for users. It would be nice if a cas.adminPagesSecurity.ldap.ldapAuthz.groupBaseDn were added (I currently need to specify a baseDn higher in the tree and do a subtree search). Sure. Submit a PR. -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected] <mailto:[email protected]> . To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/c6d58f4b-a343-435b-9cf8-d508e8a7588c%40apereo.org <https://groups.google.com/a/apereo.org/d/msgid/cas-user/c6d58f4b-a343-435b-9cf8-d508e8a7588c%40apereo.org?utm_medium=email&utm_source=footer> . -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/00ca01d27e16%24671cb2c0%2435561840%24%40unicon.net.
