Hi,

When authorizing an OAuth 2.0 client in CAS 5.0.0 to 5.0.9, I sometimes end 
up
not where I wanted. Steps to reproduce:

1. Have an OAuth service configured to work with CAS and registered in that 
CAS.
2. Visit the service and log in.
3. Log out from the service. This creates new CAS session cookie.
4. Start logging in to the service again, but don't complete the form yet.
5. Wait 10 minutes for CAS session cookie to expire, or just delete it.
6. Complete the login form and submit.
7. If You deleted the cookie, login form will show up again, empty, and - 
this
   time - lacking a service URL in address bar. Waiting for cookie 
expiration
   normally avoids the need to give credentials second time, but the URL
   is still lost. In CAS logs, a string is found:

   <No service could be extracted based on the given request>

8. In our setup, the user still lands on proper site after logging in, 
because
   we reconfigured cas.view.defaultRedirectUrl. But this won't pass if we 
get
   more OAuth clients.

I guess this has something to do with how Spring Flow handles sessions, but
can't figure myself what should I do to avoid this. Can you give any
clues, or should I fill a bug in CAS?

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/d7c2246d-5196-49d3-901d-b7ecb5ce6aa4%40apereo.org.

Reply via email to