I’d have to see the full log to make a judgement here, but for others, by all means file issues. Turn up the logs for spring security and you should see more.
As for grants and authorities, you’re perfectly fine. Do include that in the issue. --Misagh From: Menno en Erla Avegaart [mailto:[email protected]] Sent: Monday, February 6, 2017 1:25 PM To: CAS Community <[email protected]> Cc: [email protected] Subject: Re: [cas-user] Spring security problems Thanks, the first problem seems to be fixed now and I created an issue for 6+7. That leave me with the problem 2: After logging into any status page I get a 401 error, even though the log shows that authorization was successful (I get "Executing authorization for expected admin roles [{}]", not followed by "User [{}] is not authorized to access the requested resource allowed to roles [{}]"). Also, I was looking at LdapAuthenticationProvider and wondered why you are adding the attributes as authorities: authorities.addAll(profile.getAttributes().entrySet().stream().map(e -> new SimpleGrantedAuthority(e.getValue().toString())).collect(Collectors.toList())); That just seems wrong. User attributes are not authorities, only roles are! Op vrijdag 3 februari 2017 15:25:11 UTC+1 schreef Misagh Moayyed: Quick update: testing this a bit more I did find a few anomalies. I’ll put aside some time to review and apply fixes and if you want to track progress, do please open up that issue. Thanks. --Misagh From: Misagh Moayyed [mailto:[email protected] <javascript:> ] Sent: Friday, February 3, 2017 2:34 PM To: [email protected] <javascript:> Subject: RE: [cas-user] Spring security problems 1. I configured security.basic.path=/cas/status/** and it triggers for Spring Boot endpoints (e.g. /cas/status/health), but it doesn't for /cas/status/dashboard. Am I missing a config option somewhere? Possible. Difficult to say without seeing what the config looks like. 2. Are Spring Boot endpoints like /cas/status/health supposed to work? Yes. Open issues if you find the opposite is true. 3. Yes, but if you do that you bypass Spring Security and no longer have to option to validate roles (see https://github.com/apereo/cas/issues/2335). Cool. Sounds like a PR to me. 5. It does need the .type, because LdapAuthenticationProvider uses it. Yes. See my previous comment. 6. LdapUserGroupsToRolesAuthorizationGenerator is the one that deals with groups, but because it inherits from LdapUserAttributesToRolesAuthorizationGenerator it also checks the roleAttribute (in my code I temporarily moved de roleAttribute code from LdapUserAttributesToRolesAuthorizationGenerator.generate() to addProfileRoles()). If I am understanding you correctly, you’ll need to make sure only LdapUserAttributesToRolesAuthorizationGenerator is activated, and basically treat your groupAttribute as CAS’ roleAttribute if possible. _____ This email has been scanned for spam and viruses by Proofpoint Essentials. Click here <https://us2.proofpointessentials.com/index01.php?mod_id=11&mod_option=logitem&mail_id=1486383922-V5QlDmRl%2BfKa&r_address=mmoayyed%40unicon.net&report=1> to report this email as spam. = -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/00eb01d2807a%24aa2c6f90%24fe854eb0%24%40unicon.net.
