Here is the log with org.apereo.cas and org.springframework.security set to
debug.
I don't see why I'm getting a 401 error. Everything in the log looks ok...
Op maandag 6 februari 2017 14:12:35 UTC+1 schreef Misagh Moayyed:
>
> I’d have to see the full log to make a judgement here, but for others, by
> all means file issues. Turn up the logs for spring security and you should
> see more.
>
>
>
> As for grants and authorities, you’re perfectly fine. Do include that in
> the issue.
>
> --Misagh
>
>
>
> *From:* Menno en Erla Avegaart [mailto:[email protected] <javascript:>]
> *Sent:* Monday, February 6, 2017 1:25 PM
> *To:* CAS Community <[email protected] <javascript:>>
> *Cc:* [email protected] <javascript:>
> *Subject:* Re: [cas-user] Spring security problems
>
>
>
> Thanks, the first problem seems to be fixed now and I created an issue for
> 6+7.
>
>
>
> That leave me with the problem 2: After logging into any status page I get
> a 401 error, even though the log shows that authorization was successful (I
> get "Executing authorization for expected admin roles [{}]", not followed
> by "User [{}] is not authorized to access the requested resource allowed to
> roles [{}]").
>
>
>
> Also, I was looking at LdapAuthenticationProvider and wondered why you are
> adding the attributes as authorities:
>
>
>
> authorities.addAll(profile.getAttributes().entrySet().stream().map(e ->
> new
> SimpleGrantedAuthority(e.getValue().toString())).collect(Collectors.toList()));
>
>
>
> That just seems wrong. User attributes are not authorities, only roles are!
>
>
>
> Op vrijdag 3 februari 2017 15:25:11 UTC+1 schreef Misagh Moayyed:
>
> Quick update: testing this a bit more I did find a few anomalies. I’ll put
> aside some time to review and apply fixes and if you want to track
> progress, do please open up that issue.
>
>
>
> Thanks.
>
>
>
> --Misagh
>
>
>
> *From:* Misagh Moayyed [mailto:[email protected]]
> *Sent:* Friday, February 3, 2017 2:34 PM
> *To:* [email protected]
> *Subject:* RE: [cas-user] Spring security problems
>
>
>
>
>
> 1. I configured security.basic.path=/cas/status/** and it triggers for
> Spring Boot endpoints (e.g. /cas/status/health), but it doesn't for
> /cas/status/dashboard. Am I missing a config option somewhere?
>
>
>
> Possible. Difficult to say without seeing what the config looks like.
>
>
>
> 2. Are Spring Boot endpoints like /cas/status/health supposed to work?
>
>
>
> Yes. Open issues if you find the opposite is true.
>
>
>
> 3. Yes, but if you do that you bypass Spring Security and no longer have
> to option to validate roles (see https://github.com/apereo/cas/issues/2335
> ).
>
>
>
> Cool. Sounds like a PR to me.
>
>
>
> 5. It does need the .type, because LdapAuthenticationProvider uses it.
>
>
>
> Yes. See my previous comment.
>
>
>
> 6. LdapUserGroupsToRolesAuthorizationGenerator is the one that deals with
> groups, but because it inherits
> from LdapUserAttributesToRolesAuthorizationGenerator it also checks the
> roleAttribute (in my code I temporarily moved de roleAttribute code from
> LdapUserAttributesToRolesAuthorizationGenerator.generate() to
> addProfileRoles()).
>
>
>
> If I am understanding you correctly, you’ll need to make sure only
> LdapUserAttributesToRolesAuthorizationGenerator is activated, and basically
> treat your groupAttribute as CAS’ roleAttribute if possible.
>
>
>
>
>
>
>
>
> ------------------------------
>
> This email has been scanned for spam and viruses by Proofpoint Essentials.
> Click here
> <https://us2.proofpointessentials.com/index01.php?mod_id=11&mod_option=logitem&mail_id=1486383922-V5QlDmRl%2BfKa&r_address=mmoayyed%40unicon.net&report=1>
>
> to report this email as spam.
>
>
> =
>
--
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
---
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/b34204e1-0497-47da-a440-4202f4bf6b16%40apereo.org.
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/css/**']>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/css/**'>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/js/**']>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/js/**'>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/images/**']>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/images/**'>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/webjars/**']>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/webjars/**'>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/**/favicon.ico']>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/**/favicon.ico'>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/error']>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/error'>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <No matches
found>
2017-02-06 14:23:11,565 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/**'>
2017-02-06 14:23:11,567 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 1 of 12 in additional filter chain; firing Filter:
'ChannelProcessingFilter'>
2017-02-06 14:23:11,569 DEBUG
[org.springframework.security.web.access.channel.ChannelProcessingFilter] -
<Request: FilterInvocation: URL: /status/dashboard; ConfigAttributes:
[REQUIRES_SECURE_CHANNEL]>
2017-02-06 14:23:11,569 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 2 of 12 in additional filter chain; firing Filter:
'WebAsyncManagerIntegrationFilter'>
2017-02-06 14:23:11,572 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 3 of 12 in additional filter chain; firing Filter:
'SecurityContextPersistenceFilter'>
2017-02-06 14:23:11,574 DEBUG
[org.springframework.security.web.context.HttpSessionSecurityContextRepository]
- <No HttpSession currently exists>
2017-02-06 14:23:11,574 DEBUG
[org.springframework.security.web.context.HttpSessionSecurityContextRepository]
- <No SecurityContext was available from the HttpSession: null. A new one will
be created.>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 4 of 12 in additional filter chain; firing Filter:
'HeaderWriterFilter'>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 5 of 12 in additional filter chain; firing Filter: 'LogoutFilter'>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/logout', GET]>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/logout'>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/logout', POST]>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Request 'GET /status/dashboard' doesn't match 'POST /logout>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/logout', PUT]>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Request 'GET /status/dashboard' doesn't match 'PUT /logout>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/logout', DELETE]>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Request 'GET /status/dashboard' doesn't match 'DELETE /logout>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <No matches
found>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 6 of 12 in additional filter chain; firing Filter:
'BasicAuthenticationFilter'>
2017-02-06 14:23:11,581 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 7 of 12 in additional filter chain; firing Filter:
'RequestCacheAwareFilter'>
2017-02-06 14:23:11,582 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 8 of 12 in additional filter chain; firing Filter:
'SecurityContextHolderAwareRequestFilter'>
2017-02-06 14:23:11,586 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 9 of 12 in additional filter chain; firing Filter:
'AnonymousAuthenticationFilter'>
2017-02-06 14:23:11,589 DEBUG
[org.springframework.security.web.authentication.AnonymousAuthenticationFilter]
- <Populated SecurityContextHolder with anonymous token:
'org.springframework.security.authentication.AnonymousAuthenticationToken@9055286a:
Principal: anonymousUser; Credentials: [PROTECTED]; Authenticated: true;
Details:
org.springframework.security.web.authentication.WebAuthenticationDetails@59b2:
RemoteIpAddress: 10.0.0.1; SessionId: null; Granted Authorities:
ROLE_ANONYMOUS'>
2017-02-06 14:23:11,589 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 10 of 12 in additional filter chain; firing Filter:
'SessionManagementFilter'>
2017-02-06 14:23:11,590 DEBUG
[org.springframework.security.web.session.SessionManagementFilter] - <Requested
session ID 11BB2D58489AD9EB78A55C7F6DC498A1 is invalid.>
2017-02-06 14:23:11,590 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 11 of 12 in additional filter chain; firing Filter:
'ExceptionTranslationFilter'>
2017-02-06 14:23:11,590 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 12 of 12 in additional filter chain; firing Filter:
'FilterSecurityInterceptor'>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/resume']>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/resume'>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/resume/**']>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/resume/**'>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/resume.*']>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/resume.*'>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/resume/']>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/resume/'>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/dump']>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/dump'>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/dump/**']>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/dump/**'>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/dump.*']>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/dump.*'>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/dump/']>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/dump/'>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/dashboard']>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/dashboard'>
2017-02-06 14:23:11,596 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <matched>
2017-02-06 14:23:11,597 DEBUG
[org.springframework.security.web.access.intercept.FilterSecurityInterceptor] -
<Secure object: FilterInvocation: URL: /status/dashboard; Attributes:
[authenticated]>
2017-02-06 14:23:11,597 DEBUG
[org.springframework.security.web.access.intercept.FilterSecurityInterceptor] -
<Previously Authenticated:
org.springframework.security.authentication.AnonymousAuthenticationToken@9055286a:
Principal: anonymousUser; Credentials: [PROTECTED]; Authenticated: true;
Details:
org.springframework.security.web.authentication.WebAuthenticationDetails@59b2:
RemoteIpAddress: 10.0.0.1; SessionId: null; Granted Authorities: ROLE_ANONYMOUS>
2017-02-06 14:23:11,605 DEBUG
[org.springframework.security.access.vote.AffirmativeBased] - <Voter:
org.springframework.security.web.access.expression.WebExpressionVoter@30d40f78,
returned: -1>
2017-02-06 14:23:11,609 DEBUG
[org.apereo.cas.web.view.CasReloadableMessageBundle] - <No properties file
found for [classpath:custom_messages_nl_NL] - neither plain properties nor XML>
2017-02-06 14:23:11,609 DEBUG
[org.apereo.cas.web.view.CasReloadableMessageBundle] - <No properties file
found for [classpath:messages_nl_NL] - neither plain properties nor XML>
2017-02-06 14:23:11,610 DEBUG
[org.apereo.cas.web.view.CasReloadableMessageBundle] - <No properties file
found for [classpath:custom_messages_nl] - neither plain properties nor XML>
2017-02-06 14:23:11,611 DEBUG
[org.apereo.cas.web.view.CasReloadableMessageBundle] - <No properties file
found for [classpath:custom_messages] - neither plain properties nor XML>
2017-02-06 14:23:11,613 DEBUG
[org.apereo.cas.web.view.CasReloadableMessageBundle] - <Loading properties
[messages_nl.properties] with encoding 'UTF-8'>
2017-02-06 14:23:11,615 DEBUG
[org.apereo.cas.web.view.CasReloadableMessageBundle] - <Loading properties
[messages.properties] with encoding 'UTF-8'>
2017-02-06 14:23:11,617 DEBUG
[org.springframework.security.web.access.ExceptionTranslationFilter] - <Access
is denied (user is anonymous); redirecting to authentication entry point>
org.springframework.security.access.AccessDeniedException: You are not
authorized to access this resource. Contact your CAS administrator for more
info.
at
org.springframework.security.access.vote.AffirmativeBased.decide(AffirmativeBased.java:84)
~[spring-security-core-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.access.intercept.AbstractSecurityInterceptor.beforeInvocation(AbstractSecurityInterceptor.java:233)
~[spring-security-core-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.access.intercept.FilterSecurityInterceptor.invoke(FilterSecurityInterceptor.java:124)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.access.intercept.FilterSecurityInterceptor.doFilter(FilterSecurityInterceptor.java:91)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.access.ExceptionTranslationFilter.doFilter(ExceptionTranslationFilter.java:114)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.session.SessionManagementFilter.doFilter(SessionManagementFilter.java:137)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.authentication.AnonymousAuthenticationFilter.doFilter(AnonymousAuthenticationFilter.java:111)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter.doFilter(SecurityContextHolderAwareRequestFilter.java:170)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.savedrequest.RequestCacheAwareFilter.doFilter(RequestCacheAwareFilter.java:63)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.authentication.www.BasicAuthenticationFilter.doFilterInternal(BasicAuthenticationFilter.java:158)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.authentication.logout.LogoutFilter.doFilter(LogoutFilter.java:116)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.header.HeaderWriterFilter.doFilterInternal(HeaderWriterFilter.java:64)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.context.SecurityContextPersistenceFilter.doFilter(SecurityContextPersistenceFilter.java:105)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter.doFilterInternal(WebAsyncManagerIntegrationFilter.java:56)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.access.channel.ChannelProcessingFilter.doFilter(ChannelProcessingFilter.java:157)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:331)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.FilterChainProxy.doFilterInternal(FilterChainProxy.java:214)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.security.web.FilterChainProxy.doFilter(FilterChainProxy.java:177)
~[spring-security-web-4.2.1.RELEASE.jar!/:4.2.1.RELEASE]
at
org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:346)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:262)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:192)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:165)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apereo.cas.logging.web.ThreadContextMDCServletFilter.doFilter(ThreadContextMDCServletFilter.java:90)
~[cas-server-core-logging-5.1.0-RC2-SNAPSHOT.jar!/:5.1.0-RC2-SNAPSHOT]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:192)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:165)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.springframework.web.filter.RequestContextFilter.doFilterInternal(RequestContextFilter.java:99)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:192)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:165)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.springframework.web.filter.HttpPutFormContentFilter.doFilterInternal(HttpPutFormContentFilter.java:105)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:192)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:165)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.springframework.web.filter.HiddenHttpMethodFilter.doFilterInternal(HiddenHttpMethodFilter.java:81)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:192)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:165)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.springframework.boot.actuate.autoconfigure.MetricsFilter.doFilterInternal(MetricsFilter.java:106)
~[spring-boot-actuator-1.5.1.RELEASE.jar!/:1.5.1.RELEASE]
at
org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:192)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:165)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:197)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
~[spring-web-4.3.6.RELEASE.jar!/:4.3.6.RELEASE]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:192)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:165)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:198)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:108)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:472)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:140)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:79)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:87)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:620)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.valves.RemoteIpValve.invoke(RemoteIpValve.java:677)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:349)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:784)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:66)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:802)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1410)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at
org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)
[?:1.8.0_101]
at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
[?:1.8.0_101]
at
org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
~[tomcat-embed-core-8.5.5.jar!/:8.5.5]
at java.lang.Thread.run(Unknown Source) [?:1.8.0_101]
2017-02-06 14:23:11,617 DEBUG
[org.springframework.security.web.util.matcher.AndRequestMatcher] - <Trying to
match using NegatedRequestMatcher [requestMatcher=Ant
[pattern='/**/favicon.ico']]>
2017-02-06 14:23:11,617 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/**/favicon.ico'>
2017-02-06 14:23:11,618 DEBUG
[org.springframework.security.web.util.matcher.NegatedRequestMatcher] -
<matches = true>
2017-02-06 14:23:11,618 DEBUG
[org.springframework.security.web.util.matcher.AndRequestMatcher] - <Trying to
match using NegatedRequestMatcher [requestMatcher=MediaTypeRequestMatcher
[contentNegotiationStrategy=org.springframework.web.accept.ContentNegotiationManager@743d0d44,
matchingMediaTypes=[application/json], useEquals=false,
ignoredMediaTypes=[*/*]]]>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] -
<httpRequestMediaTypes=[text/html, application/xhtml+xml, image/webp,
application/xml;q=0.9, */*;q=0.8]>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] -
<Processing text/html>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] -
<application/json .isCompatibleWith text/html = false>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] -
<Processing application/xhtml+xml>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] -
<application/json .isCompatibleWith application/xhtml+xml = false>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] -
<Processing image/webp>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] -
<application/json .isCompatibleWith image/webp = false>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] -
<Processing application/xml;q=0.9>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] -
<application/json .isCompatibleWith application/xml;q=0.9 = false>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] -
<Processing */*;q=0.8>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] -
<Ignoring>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.MediaTypeRequestMatcher] - <Did
not match any media types>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.NegatedRequestMatcher] -
<matches = true>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.AndRequestMatcher] - <Trying to
match using NegatedRequestMatcher [requestMatcher=RequestHeaderRequestMatcher
[expectedHeaderName=X-Requested-With, expectedHeaderValue=XMLHttpRequest]]>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.NegatedRequestMatcher] -
<matches = true>
2017-02-06 14:23:11,622 DEBUG
[org.springframework.security.web.util.matcher.AndRequestMatcher] - <All
requestMatchers returned true>
2017-02-06 14:23:11,642 DEBUG
[org.springframework.security.web.savedrequest.HttpSessionRequestCache] -
<DefaultSavedRequest added to Session:
DefaultSavedRequest[https://casserver:8443/cas/status/dashboard]>
2017-02-06 14:23:11,642 DEBUG
[org.springframework.security.web.access.ExceptionTranslationFilter] - <Calling
Authentication entry point.>
2017-02-06 14:23:11,642 DEBUG
[org.springframework.security.web.context.HttpSessionSecurityContextRepository]
- <SecurityContext is empty or contents are anonymous - context will not be
stored in HttpSession.>
2017-02-06 14:23:11,642 DEBUG
[org.springframework.security.web.context.SecurityContextPersistenceFilter] -
<SecurityContextHolder now cleared, as request processing completed>
2017-02-06 14:23:11,735 DEBUG
[org.apereo.cas.authentication.principal.WebApplicationServiceFactory] - <No
service is specified in the request. Skipping service creation>
2017-02-06 14:23:11,735 DEBUG
[org.apereo.cas.web.support.DefaultArgumentExtractor] - <No service could be
extracted based on the given request>
2017-02-06 14:23:11,735 DEBUG
[org.apereo.cas.web.support.AbstractArgumentExtractor] - <Extractor did not
generate service.>
2017-02-06 14:23:12,504 WARN
[nz.net.ultraq.thymeleaf.expressions.ExpressionProcessor] - <Fragment
expression "layout" is being wrapped as a Thymeleaf 3 fragment expression
(~{...}) for backwards compatibility purposes. This wrapping will be dropped
in the next major version of the expression processor, so please rewrite as a
Thymeleaf 3 fragment expression to future-proof your code. See
https://github.com/thymeleaf/thymeleaf/issues/451 for more information.>
2017-02-06 14:23:19,770 DEBUG
[org.apereo.cas.otp.repository.token.OneTimeTokenRepositoryCleaner] - <Starting
to clean previously used authenticator tokens from
[JpaGoogleAuthenticatorTokenRepository] at
[2017-02-06T14:23:19.770+01:00[Europe/Berlin]]>
2017-02-06 14:23:19,770 DEBUG
[org.apereo.cas.otp.repository.token.BaseOneTimeTokenRepository] - <Starting to
clean expiring and previously used google authenticator tokens>
2017-02-06 14:23:19,916 DEBUG
[org.apereo.cas.adaptors.gauth.JpaGoogleAuthenticatorTokenRepository] -
<Deleted [0] expired previously used token record(s)>
2017-02-06 14:23:19,951 INFO
[org.apereo.cas.otp.repository.token.BaseOneTimeTokenRepository] - <Finished
cleaning google authenticator tokens>
2017-02-06 14:23:19,951 INFO
[org.apereo.cas.otp.repository.token.OneTimeTokenRepositoryCleaner] - <Finished
cleaning authenticator tokens at [2017-02-06T14:23:19.951+01:00[Europe/Berlin]]>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/css/**']>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/css/**'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/js/**']>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/js/**'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/images/**']>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/images/**'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/webjars/**']>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/webjars/**'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/**/favicon.ico']>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/**/favicon.ico'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/error']>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/error'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <No matches
found>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/**'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 1 of 12 in additional filter chain; firing Filter:
'ChannelProcessingFilter'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.access.channel.ChannelProcessingFilter] -
<Request: FilterInvocation: URL: /status/dashboard; ConfigAttributes:
[REQUIRES_SECURE_CHANNEL]>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 2 of 12 in additional filter chain; firing Filter:
'WebAsyncManagerIntegrationFilter'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 3 of 12 in additional filter chain; firing Filter:
'SecurityContextPersistenceFilter'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.context.HttpSessionSecurityContextRepository]
- <HttpSession returned null object for SPRING_SECURITY_CONTEXT>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.context.HttpSessionSecurityContextRepository]
- <No SecurityContext was available from the HttpSession:
org.apache.catalina.session.StandardSessionFacade@517c7977. A new one will be
created.>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 4 of 12 in additional filter chain; firing Filter:
'HeaderWriterFilter'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 5 of 12 in additional filter chain; firing Filter: 'LogoutFilter'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/logout', GET]>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/logout'>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/logout', POST]>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Request 'GET /status/dashboard' doesn't match 'POST /logout>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/logout', PUT]>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Request 'GET /status/dashboard' doesn't match 'PUT /logout>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/logout', DELETE]>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Request 'GET /status/dashboard' doesn't match 'DELETE /logout>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <No matches
found>
2017-02-06 14:23:31,904 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 6 of 12 in additional filter chain; firing Filter:
'BasicAuthenticationFilter'>
2017-02-06 14:23:31,910 DEBUG
[org.springframework.security.web.authentication.www.BasicAuthenticationFilter]
- <Basic Authentication Authorization header found for user 'admin'>
2017-02-06 14:23:31,912 DEBUG
[org.springframework.security.authentication.ProviderManager] - <Authentication
attempt using org.apereo.cas.web.ldap.LdapAuthenticationProvider>
2017-02-06 14:23:31,916 DEBUG [org.apereo.cas.configuration.support.Beans] -
<Creating direct-bind authenticator for [ldaps://ldapserver]>
2017-02-06 14:23:31,916 DEBUG [org.apereo.cas.configuration.support.Beans] -
<Creating LDAP connection factory for [ldaps://ldapserver]>
2017-02-06 14:23:31,916 DEBUG [org.apereo.cas.configuration.support.Beans] -
<Creating LDAP connection configuration for [ldaps://ldapserver]>
2017-02-06 14:23:31,916 DEBUG [org.apereo.cas.configuration.support.Beans] -
<Creating LDAP SSL configuration via keystore [classpath:/keystore.jks]>
2017-02-06 14:23:31,916 DEBUG [org.apereo.cas.configuration.support.Beans] -
<Creating LDAP bind connection initializer via [cn=administrator]>
2017-02-06 14:23:31,916 DEBUG [org.apereo.cas.configuration.support.Beans] -
<Creating LDAP connection pool configuration for [ldaps://ldapserver]>
2017-02-06 14:23:31,916 DEBUG [org.apereo.cas.configuration.support.Beans] -
<No validator is configured for the LDAP connection pool of
[ldaps://ldapserver]>
2017-02-06 14:23:31,916 DEBUG [org.apereo.cas.configuration.support.Beans] -
<Initializing ldap connection pool for [ldaps://ldapserver] and bindDn
[cn=administrator]>
2017-02-06 14:23:35,040 DEBUG
[org.apereo.cas.web.ldap.LdapAuthenticationProvider] - <LDAP response:
[[org.ldaptive.auth.AuthenticationResponse@1649320156::authenticationResultCode=AUTHENTICATION_HANDLER_SUCCESS,
resolvedDn=uid=admin,ou=people,dc=domain, ldapEntry=[...]]]>
2017-02-06 14:23:35,054 DEBUG
[org.apereo.cas.web.ldap.LdapAuthenticationProvider] - <Collected user profile
[#CommonProfile# | id: admin | attributes: {...} | roles: [] | permissions: []
| isRemembered: false |]>
2017-02-06 14:23:35,054 DEBUG
[org.apereo.cas.authorization.LdapUserAttributesToRolesAuthorizationGenerator]
- <Attempting to get details for user [admin].>
2017-02-06 14:23:35,054 DEBUG [org.apereo.cas.configuration.support.Beans] -
<Constructed LDAP search filter [(&(uid=admin)(objectclass=inetOrgPerson))]>
2017-02-06 14:23:35,199 DEBUG
[org.apereo.cas.authorization.LdapUserAttributesToRolesAuthorizationGenerator]
- <LDAP user search response:
[[org.ldaptive.Response@1845287149::result=[org.ldaptive.SearchResult@1660001264::entries=[[...]]>
2017-02-06 14:23:35,199 DEBUG
[org.apereo.cas.authorization.LdapUserGroupsToRolesAuthorizationGenerator] -
<Attempting to get roles for user [uid=admin,ou=people,dc=domain].>
2017-02-06 14:23:35,199 DEBUG [org.apereo.cas.configuration.support.Beans] -
<Constructed LDAP search filter
[(&(uniquemember=uid=admin,ou=people,dc=domain)(objectclass=groupOfUniqueNames))]>
2017-02-06 14:23:40,641 DEBUG
[org.apereo.cas.authorization.LdapUserGroupsToRolesAuthorizationGenerator] -
<LDAP role search response: ...
2017-02-06 14:23:40,643 WARN
[org.apereo.cas.authorization.LdapUserAttributesToRolesAuthorizationGenerator]
- <LDAP cn=support>
2017-02-06 14:23:40,645 DEBUG
[org.apereo.cas.web.ldap.LdapAuthenticationProvider] - <Assembled user profile
with roles after generating authorization claims [#CommonProfile# | id: admin |
attributes: {...} | roles: [ROLE_SUPPORT] | permissions: [] | isRemembered:
false |]>
2017-02-06 14:23:40,647 DEBUG
[org.apereo.cas.web.ldap.LdapAuthenticationProvider] - <List of authorities
remapped from profile roles are [[[...]]>
2017-02-06 14:23:40,654 DEBUG
[org.apereo.cas.web.ldap.LdapAuthenticationProvider] - <Executing authorization
for expected admin roles [[ROLE_SUPPORT]]>
2017-02-06 14:23:40,661 DEBUG
[org.springframework.security.web.authentication.www.BasicAuthenticationFilter]
- <Authentication success:
org.springframework.security.authentication.UsernamePasswordAuthenticationToken@5eb7b071:
Principal: admin; Credentials: [PROTECTED]; Authenticated: true; Details:
org.springframework.security.web.authentication.WebAuthenticationDetails@0:
RemoteIpAddress: 10.0.0.1; SessionId: 242B45F067AE713E3CBD060FA79593B5; Granted
Authorities: [...>
2017-02-06 14:23:40,661 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 7 of 12 in additional filter chain; firing Filter:
'RequestCacheAwareFilter'>
2017-02-06 14:23:40,661 DEBUG
[org.springframework.security.web.savedrequest.DefaultSavedRequest] -
<pathInfo: both null (property equals)>
2017-02-06 14:23:40,661 DEBUG
[org.springframework.security.web.savedrequest.DefaultSavedRequest] -
<queryString: both null (property equals)>
2017-02-06 14:23:40,661 DEBUG
[org.springframework.security.web.savedrequest.DefaultSavedRequest] -
<requestURI: arg1=/cas/status/dashboard; arg2=/cas/status/dashboard (property
equals)>
2017-02-06 14:23:40,661 DEBUG
[org.springframework.security.web.savedrequest.DefaultSavedRequest] -
<serverPort: arg1=8443; arg2=8443 (property equals)>
2017-02-06 14:23:40,661 DEBUG
[org.springframework.security.web.savedrequest.DefaultSavedRequest] -
<requestURL: arg1=https://casserver:8443/cas/status/dashboard;
arg2=https://casserver:8443/cas/status/dashboard (property equals)>
2017-02-06 14:23:40,661 DEBUG
[org.springframework.security.web.savedrequest.DefaultSavedRequest] - <scheme:
arg1=https; arg2=https (property equals)>
2017-02-06 14:23:40,661 DEBUG
[org.springframework.security.web.savedrequest.DefaultSavedRequest] -
<serverName: arg1=casserver; arg2=casserver (property equals)>
2017-02-06 14:23:40,661 DEBUG
[org.springframework.security.web.savedrequest.DefaultSavedRequest] -
<contextPath: arg1=/cas; arg2=/cas (property equals)>
2017-02-06 14:23:40,661 DEBUG
[org.springframework.security.web.savedrequest.DefaultSavedRequest] -
<servletPath: arg1=/status/dashboard; arg2=/status/dashboard (property equals)>
2017-02-06 14:23:40,662 DEBUG
[org.springframework.security.web.savedrequest.HttpSessionRequestCache] -
<Removing DefaultSavedRequest from session if present>
2017-02-06 14:23:40,666 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 8 of 12 in additional filter chain; firing Filter:
'SecurityContextHolderAwareRequestFilter'>
2017-02-06 14:23:40,666 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 9 of 12 in additional filter chain; firing Filter:
'AnonymousAuthenticationFilter'>
2017-02-06 14:23:40,667 DEBUG
[org.springframework.security.web.authentication.AnonymousAuthenticationFilter]
- <SecurityContextHolder not populated with anonymous token, as it already
contained:
'org.springframework.security.authentication.UsernamePasswordAuthenticationToken@5eb7b071:
Principal: admin; Credentials: [PROTECTED]; Authenticated: true; Details:
org.springframework.security.web.authentication.WebAuthenticationDetails@0:
RemoteIpAddress: 10.0.0.1; SessionId: 242B45F067AE713E3CBD060FA79593B5; Granted
Authorities: [...'>
2017-02-06 14:23:40,667 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 10 of 12 in additional filter chain; firing Filter:
'SessionManagementFilter'>
2017-02-06 14:23:40,667 DEBUG
[org.springframework.security.web.authentication.session.CompositeSessionAuthenticationStrategy]
- <Delegating to
org.springframework.security.web.authentication.session.ChangeSessionIdAuthenticationStrategy@20a47036>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.context.HttpSessionSecurityContextRepository]
- <SecurityContext
'org.springframework.security.core.context.SecurityContextImpl@5eb7b071:
Authentication:
org.springframework.security.authentication.UsernamePasswordAuthenticationToken@5eb7b071:
Principal: admin; Credentials: [PROTECTED]; Authenticated: true; Details:
org.springframework.security.web.authentication.WebAuthenticationDetails@0:
RemoteIpAddress: 10.0.0.1; SessionId: 242B45F067AE713E3CBD060FA79593B5; Granted
Authorities: [...' stored to HttpSession:
'org.apache.catalina.session.StandardSessionFacade@517c7977>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 11 of 12 in additional filter chain; firing Filter:
'ExceptionTranslationFilter'>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard at
position 12 of 12 in additional filter chain; firing Filter:
'FilterSecurityInterceptor'>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/resume']>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/resume'>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/resume/**']>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/resume/**'>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/resume.*']>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/resume.*'>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/resume/']>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/resume/'>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/dump']>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/dump'>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/dump/**']>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/dump/**'>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/dump.*']>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/dump.*'>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/dump/']>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/dump/'>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/status/dashboard']>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/status/dashboard'; against '/status/dashboard'>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <matched>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.access.intercept.FilterSecurityInterceptor] -
<Secure object: FilterInvocation: URL: /status/dashboard; Attributes:
[authenticated]>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.access.intercept.FilterSecurityInterceptor] -
<Previously Authenticated:
org.springframework.security.authentication.UsernamePasswordAuthenticationToken@5eb7b071:
Principal: admin; Credentials: [PROTECTED]; Authenticated: true; Details:
org.springframework.security.web.authentication.WebAuthenticationDetails@0:
RemoteIpAddress: 10.0.0.1; SessionId: 242B45F067AE713E3CBD060FA79593B5; Granted
Authorities: [...>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.access.vote.AffirmativeBased] - <Voter:
org.springframework.security.web.access.expression.WebExpressionVoter@30d40f78,
returned: 1>
2017-02-06 14:23:40,668 DEBUG
[org.springframework.security.web.access.intercept.FilterSecurityInterceptor] -
<Authorization successful>
2017-02-06 14:23:40,669 DEBUG
[org.springframework.security.web.access.intercept.FilterSecurityInterceptor] -
<RunAsManager did not change Authentication object>
2017-02-06 14:23:40,669 DEBUG
[org.springframework.security.web.FilterChainProxy] - </status/dashboard
reached end of additional filter chain; proceeding with original chain>
2017-02-06 14:23:40,779 DEBUG
[org.springframework.security.web.context.HttpSessionSecurityContextRepository]
- <SecurityContext
'org.springframework.security.core.context.SecurityContextImpl@5eb7b071:
Authentication:
org.springframework.security.authentication.UsernamePasswordAuthenticationToken@5eb7b071:
Principal: admin; Credentials: [PROTECTED]; Authenticated: true; Details:
org.springframework.security.web.authentication.WebAuthenticationDetails@0:
RemoteIpAddress: 10.0.0.1; SessionId: 242B45F067AE713E3CBD060FA79593B5; Granted
Authorities: [...' stored to HttpSession:
'org.apache.catalina.session.StandardSessionFacade@517c7977>
2017-02-06 14:23:40,781 DEBUG
[org.springframework.security.web.access.ExceptionTranslationFilter] - <Chain
processed normally>
2017-02-06 14:23:40,781 DEBUG
[org.springframework.security.web.context.SecurityContextPersistenceFilter] -
<SecurityContextHolder now cleared, as request processing completed>
2017-02-06 14:23:40,845 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/css/**']>
2017-02-06 14:23:40,845 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/js/cas.js'; against '/css/**'>
2017-02-06 14:23:40,845 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/js/**']>
2017-02-06 14:23:40,845 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/js/cas.js'; against '/js/**'>
2017-02-06 14:23:40,845 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <matched>
2017-02-06 14:23:40,845 DEBUG
[org.springframework.security.web.FilterChainProxy] - </js/cas.js has an empty
filter list>
2017-02-06 14:23:40,883 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/css/**']>
2017-02-06 14:23:40,883 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/css/cas.css'; against '/css/**'>
2017-02-06 14:23:40,883 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <matched>
2017-02-06 14:23:40,883 DEBUG
[org.springframework.security.web.FilterChainProxy] - </css/cas.css has an
empty filter list>
2017-02-06 14:23:41,015 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/css/**']>
2017-02-06 14:23:41,015 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/images/cas-logo.png'; against '/css/**'>
2017-02-06 14:23:41,015 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/js/**']>
2017-02-06 14:23:41,015 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/images/cas-logo.png'; against '/js/**'>
2017-02-06 14:23:41,015 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/images/**']>
2017-02-06 14:23:41,015 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/images/cas-logo.png'; against '/images/**'>
2017-02-06 14:23:41,015 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <matched>
2017-02-06 14:23:41,015 DEBUG
[org.springframework.security.web.FilterChainProxy] - </images/cas-logo.png has
an empty filter list>
2017-02-06 14:23:41,018 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/css/**']>
2017-02-06 14:23:41,018 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/images/apereo-logo.png'; against '/css/**'>
2017-02-06 14:23:41,018 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/js/**']>
2017-02-06 14:23:41,018 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/images/apereo-logo.png'; against '/js/**'>
2017-02-06 14:23:41,018 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <Trying to
match using Ant [pattern='/images/**']>
2017-02-06 14:23:41,018 DEBUG
[org.springframework.security.web.util.matcher.AntPathRequestMatcher] -
<Checking match of request : '/images/apereo-logo.png'; against '/images/**'>
2017-02-06 14:23:41,018 DEBUG
[org.springframework.security.web.util.matcher.OrRequestMatcher] - <matched>
2017-02-06 14:23:41,018 DEBUG
[org.springframework.security.web.FilterChainProxy] - </images/apereo-logo.png
has an empty filter list>