Hi, 

We want to disable http session for our Rest endpoints in our application 
using CAS version 5.1.4. 

In other APIs we have built, creating a configuration class like this is 
enough:

*@EnableWebSecurity*
*@Order(1)*
*public class RestSecurityConfig extends WebSecurityConfigurerAdapter {*

*   @Override*
*    protected void configure(final HttpSecurity http) throws Exception {*
*        
http.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS);*
*        http.csrf().disable();*
*    }*
*}*

But if we add this to our app, the config is loaded when starting the app, 
but not applied, as when trying any request you find that there is session 
in it. 

Is there any way we can do this?


Thanks in advance,
Juan.

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/a7ec8ed5-3622-4587-844e-ba7775c3e323%40apereo.org.

Reply via email to