If you put parameters like that in the URL, it'd be a HUGE security
risk...username and password would be stored in cleartext in browser history,
server logs, possibly firewall/load balancer logs, etc.
There is this workaround that you can do though; this hasn't been tested with
CAS 5, but does work with 3.x and 4.x; code has been anonymized a bit and some
pieces chopped out, but this should give you a good starting point. It also
comes with the usual "no warranties, make sure you know what this is doing, use
at your own risk" disclaimer. And, make sure you secure this somehow so that
only a very select, heavily audited group of folks can use it...!! (There are
extra steps with this stuff posted below that can potentially be eliminated,
but they offer the ability to add extra layers of protection.)
Post username to this URL:
/path/to/emulate.jsp
Which contains stuff like this:
<%@page contentType="text/html; charset=windows-1252" isELIgnored="false"
%>
<%
try {
String userName = request.getParameter("username");
String userPassword = "";
try {
if (request.getParameter("username") != "") {
userPassword = howeverYouGetThePasswordForTheUser(userName);
}
%>
<html>
<body onload='setTimeout("document.forms.logon.submit()",1000)'>
<! ame src='https://servername.domain.com/public/logout.jsp' width='0'
height='0'><! rame>
Loading...
<form name="logon" method="post"
action="https://<%=config.getServletContext().getInitParameter("casServer").toLowerCase()%>/casLogin.jsp">
<input type="hidden" name="username" value="<%=userName%>">
<input type="hidden" name="password" value="<%=userPassword%>">
</form>
</body>
</html>
<%
} catch (Exception e) {
e.printStackTrace(new java.io.PrintWriter(out));
String myException = String.valueOf(e);
}
} catch (Exception e) {
e.printStackTrace(new java.io.PrintWriter(out));
String myException = String.valueOf(e);
}
%>
Which posts to this file that you put in your CAS server's Tomcat ROOT folder
(so that it will look something like https://cas.something.com/casLogin.jsp) ::
<%@page contentType="text/html; charset=windows-1252" isELIgnored="false"
import="java.net.URL"
import="java.net.HttpURLConnection"
import="java.io.InputStream"
import="java.io.BufferedReader"
import="java.io.InputStreamReader"
%>
<%
response.setHeader("Cache-Control","no-cache"); //HTTP 1.1
response.setHeader("Pragma","no-cache"); //HTTP 1.0
response.setDateHeader ("Expires", -1); //prevents caching at the proxy server
String testURL = "https://" + String.valueOf(request.getServerName()) +
"/cas/login";
String myService = request.getParameter("service");
String myReferer = request.getHeader("referer");
String username = request.getParameter("username");
String password = request.getParameter("password");
if (myReferer == null) { myReferer = ""; }
if ((myService != null) && (myService != "")) {
testURL = testURL + "?service=" + myService;
} else if (myReferer.indexOf("emulate") > -1) { //If called from the
"emulate.jsp" page, redirect to the root of the secured path
testURL = testURL + "?service=" + "https%3A%2F%2F" +
"servername.domain.com" + "%2Fservlet%2FsecuredPath%2F";
}
String myLT = "";
String myExecution = "";
URL myUrl = new URL(testURL);
HttpURLConnection myUrlConnection = (HttpURLConnection)myUrl.openConnection();
myUrlConnection.setDoInput(true);
myUrlConnection.setDoOutput(false);
String myCookie = myUrlConnection.getHeaderField("Set-Cookie");
myUrlConnection = (HttpURLConnection)myUrl.openConnection();
if (myCookie != null) {
myUrlConnection.setRequestProperty("Cookie", myCookie);
}
myUrlConnection.setDoInput(true);
myUrlConnection.setDoOutput(false);
response.addHeader("Set-Cookie", myCookie);
response.setContentType("text/html");
if (null != (myCookie = myUrlConnection.getHeaderField("Set-Cookie"))) {
response.addHeader("Set-Cookie", myCookie);
}
InputStream webContent = (InputStream)myUrlConnection.getInputStream();
BufferedReader pageStream = new BufferedReader (new InputStreamReader
(webContent));
String currentLine = "";
String debugOutput = "";
if (myUrlConnection.getResponseCode() == 200){ //Makes sure that the page
pulled correctly and didn't give an error
while ((currentLine = pageStream.readLine()) != null) {
if (currentLine.toLowerCase().indexOf("name=\"lt\"") > -1) {
myLT = currentLine.substring(currentLine.indexOf("value=") +
7,currentLine.length() - 4);
} else if (currentLine.toLowerCase().indexOf("name=\"execution\"") > -1) {
myExecution = currentLine.substring(currentLine.indexOf("value=") +
7,currentLine.length() - 4);
}
}
}
pageStream.close();
%>
<html>
<head>
<META HTTP-EQUIV="Pragma" CONTENT="no-cache">
<META HTTP-EQUIV="Expires" CONTENT="-1">
</head>
<body onload="document.forms.loginForm.submit()">
Loading...
<form name="loginForm" action="<%=testURL%>" method="POST">
<input type="hidden" name="username" value="<%=username%>">
<input type="hidden" name="password" value="<%=password%>">
<input type="hidden" name="lt" value="<%=myLT%>" />
<input type="hidden" name="execution" value="<%=myExecution%>">
<input type="hidden" name="_eventId" value="submit" />
</form>
</body>
</html>
>>> Richard Yang <[email protected]> 02/02/17 2:47 PM >>>
I am using cas 4.2.7http://localhost/cas/login?username=xxx&password=yyyy just
gives me the default cas login page.
I understand I may need to attache a "login ticket" if not submitting a login
form, but how to get a login ticket?
The reason I want to use the cas login api in http request is to integrate cas
sso with our existing login page.
Please do not tell me I can custom my current login page with cas's jsp form
based login. It is just too much work and jsp to us is a very old technology
and not to be considered for new development.
Thanks.
Richard
--
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
---
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an
email to [email protected].
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/3a86ad29-c804-4c44-bc57-6389fdf2bd67%40apereo.org.
--
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
---
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/5894383B020000450007E1E3%40mugwgate.millikin.edu.