I
think I
found the issue.
The comments in the example say "
Choose the provider you need from the above map (i.e. 'mfa-duo`)
"
, however the actual value for Duo is
"duoMultifactorAuthenticationProvider".
final MultifactorAuthenticationProvider provider =
providerMap.get("duoMultifactorAuthenticationProvider");
Adam
On Thu, Dec 7, 2017 at 10:43 AM, Adam Causey <[email protected]> wrote:
> Misagh,
>
> Do you have any other examples of the custom triggers? I have written a
> custom trigger but am getting a NullPointerException as follows:
>
> 2017-12-07 10:36:53,826 [https-jsse-nio-8444-exec-1] WARN
> org.apereo.cas.web.flow.resolver.impl.InitialAuthenticationAttemptWebflowEventResolver
> - null
>
> java.lang.NullPointerException: null
>
> at edu.vcu.cas.duo.web.CustomWebFlowEventResolver.resolveInternal(
> CustomWebFlowEventResolver.java:53) ~[classes!/:5.1.4]
>
> at org.apereo.cas.web.flow.resolver.impl.AbstractCasWebflowEventResolve
> r.resolve(AbstractCasWebflowEventResolver.java:475)
> ~[cas-server-core-webflow-5.1.4.jar!/:5.1.4]
>
> at org.apereo.cas.web.flow.resolver.impl.AbstractCasWebflowEventResolve
> r.resolveSingle(AbstractCasWebflowEventResolver.java:480)
> ~[cas-server-core-webflow-5.1.4.jar!/:5.1.4]
>
> ...
>
>
> This is the configuration class
>
>
> @Configuration("customWebFlowEventResolverConfiguration")
>
> @EnableConfigurationProperties(CasConfigurationProperties.class)
>
> public class CustomWebFlowEventResolverConfiguration {
>
>
> @Autowired
>
> @Qualifier("initialAuthenticationAttemptWebflowEventResolver")
>
> private CasDelegatingWebflowEventResolver initialEventResolver;
>
>
> @Autowired
>
> @Qualifier("centralAuthenticationService")
>
> private CentralAuthenticationService centralAuthenticationService;
>
>
> @Autowired
>
> @Qualifier("defaultAuthenticationSystemSupport")
>
> private AuthenticationSystemSupport authenticationSystemSupport;
>
>
> @Autowired
>
> @Qualifier("defaultTicketRegistrySupport")
>
> private TicketRegistrySupport ticketRegistrySupport;
>
>
> @Autowired
>
> @Qualifier("servicesManager")
>
> private ServicesManager servicesManager;
>
>
> @Autowired(required = false)
>
> @Qualifier("multifactorAuthenticationProviderSelector")
>
> private MultifactorAuthenticationProviderSelector
> multifactorAuthenticationProviderSelector = new
> RankedMultifactorAuthenticationProviderSelector();
>
>
> @Autowired
>
> @Qualifier("warnCookieGenerator")
>
> private CookieGenerator warnCookieGenerator;
>
>
> @Autowired
>
> @Qualifier("authenticationServiceSelectionPlan")
>
> private AuthenticationServiceSelectionPlan authenticationRequestServiceSe
> lectionStrategies;
>
>
> @RefreshScope
>
> @Bean
>
> public CasWebflowEventResolver customWebflowEventResolver() {
>
> return new CustomWebFlowEventResolver(authenticationSystemSupport,
> centralAuthenticationService,
>
> servicesManager, ticketRegistrySupport, warnCookieGenerator,
>
> authenticationRequestServiceSelectionStrategies,
> multifactorAuthenticationProviderSelector);
>
> }
>
>
> @PostConstruct
>
> public void initialize() {
>
> initialEventResolver.addDelegate(customWebflowEventResolver());
>
> }
>
>
> }
>
> This is the WebflowEventResolver:
>
>
> public class CustomWebFlowEventResolver extends
> AbstractCasWebflowEventResolver {
>
>
> public CustomWebFlowEventResolver(AuthenticationSystemSupport
> authenticationSystemSupport,
>
> CentralAuthenticationService centralAuthenticationService,
> ServicesManager servicesManager,
>
> TicketRegistrySupport ticketRegistrySupport, CookieGenerator
> warnCookieGenerator,
>
> AuthenticationServiceSelectionPlan authenticationSelectionStrategies,
>
> MultifactorAuthenticationProviderSelector selector) {
>
> super(authenticationSystemSupport, centralAuthenticationService,
> servicesManager, ticketRegistrySupport,
>
> warnCookieGenerator, authenticationSelectionStrategies, selector);
>
> }
>
>
> @Override
>
> public Set<Event> resolveInternal(RequestContext context) {
>
> final RegisteredService service = WebUtils.getRegisteredService(context);
>
> final Authentication authentication = WebUtils.getAuthentication(context);
>
>
> final Map<String, MultifactorAuthenticationProvider> providerMap =
> WebUtils
>
> .getAvailableMultifactorAuthenticationProviders(applicationContext);
>
> final MultifactorAuthenticationProvider provider = providerMap.get(
> "mfa-duo");
>
> final Map eventAttributes =
> buildEventAttributeMap(authentication.getPrincipal(),
> service,
>
> provider);
>
> final Event event = validateEventIdForMatchingTransitionInContext(provider
> .getId(), context, eventAttributes);
>
> return ImmutableSet.of(event);
>
> }
>
>
> }
>
>
>
> I have registered the Configuration in the META-INF/spring.factories
> configuration file.
>
>
> Thanks,
> Adam
>
>
> On Tue, Dec 5, 2017 at 8:13 PM, Misagh Moayyed <[email protected]>
> wrote:
>
>> Caching can be controlled but it’s today based on a per-app basis:
>> https://apereo.github.io/cas/5.2.x/integration/Attribute-Rel
>> ease-Caching.html
>>
>> Also, it might better to review this page for options that handle bypass
>> more dynamically:
>> https://apereo.github.io/cas/5.2.x/installation/Configuring-
>> Multifactor-Authentication-Bypass.html
>>
>> …which should get invoked every time.
>>
>> --Misagh
>>
>> ------------------------------
>>
>> *From: *"Adam Causey" <[email protected]>
>> *To: *[email protected]
>> *Sent: *Tuesday, December 5, 2017 1:39:54 PM
>>
>> *Subject: *Re: [cas-user] Customized MFA bypass in CAS 5.1.x
>>
>> Is there a way to not cache the attributes that are retrieved via a
>> Groovy script? I noticed they are cached, and I need the bypass check to
>> occur on every login, including the SSO logins.
>>
>> Thanks,
>> Adam
>>
>> On Thu, Oct 19, 2017 at 1:14 PM, Misagh Moayyed <[email protected]>
>> wrote:
>>
>>> Sorry; too many versions to keep track of. I was of thinking of 5.2
>>> where you can hit a rest endpoint and have it return attributes for you. No
>>> such thing in 5.1. My bad. Alternatively, you write a groovy script that
>>> would do the same.
>>> https://apereo.github.io/cas/5.1.x/installation/Configuratio
>>> n-Properties.html#groovy
>>>
>>> ------------------------------
>>>
>>> *From: *"Adam Causey" <[email protected]>
>>> *To: *[email protected]
>>> *Sent: *Thursday, October 19, 2017 9:59:05 AM
>>> *Subject: *Re: [cas-user] Customized MFA bypass in CAS 5.1.x
>>>
>>> How and where would I populate the Principal? Are there any examples you
>>> could provide.
>>>
>>> Thanks,
>>> Adam
>>>
>>> On Thu, Oct 19, 2017 at 12:46 PM, Misagh Moayyed <[email protected]>
>>> wrote:
>>>
>>>> Not unless you write your own trigger. One other option would be to
>>>> make the REST call and populate the principal with an attribute that says
>>>> "bypass=true". Then let the bypass logic use that attribute. Likely more
>>>> performant.
>>>>
>>>> ------------------------------
>>>>
>>>> *From: *"Adam Causey" <[email protected]>
>>>> *To: *[email protected]
>>>> *Sent: *Thursday, October 19, 2017 8:52:20 AM
>>>> *Subject: *[cas-user] Customized MFA bypass in CAS 5.1.x
>>>>
>>>> Is there a way to add our own custom bypass logic to CAS 5.1.x?
>>>> Specifically I would like to make a call to a RESTful API that returns a
>>>> boolean value that says whether the user can bypass or not.
>>>>
>>>> Thanks,
>>>> Adam
>>>>
>>>> --
>>>> - Website: https://apereo.github.io/cas
>>>> - Gitter Chatroom: https://gitter.im/apereo/cas
>>>> - List Guidelines: https://goo.gl/1VRrw7
>>>> - Contributions: https://goo.gl/mh7qDG
>>>> ---
>>>> You received this message because you are subscribed to the Google
>>>> Groups "CAS Community" group.
>>>> To unsubscribe from this group and stop receiving emails from it, send
>>>> an email to [email protected].
>>>> To view this discussion on the web visit https://groups.google.com/a/ap
>>>> ereo.org/d/msgid/cas-user/CAN6MV5ON1ibwsupJjYCJ2cnF3MA4OXnzo
>>>> qH%2B29pwiP8OLY%2BX2Q%40mail.gmail.com
>>>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAN6MV5ON1ibwsupJjYCJ2cnF3MA4OXnzoqH%2B29pwiP8OLY%2BX2Q%40mail.gmail.com?utm_medium=email&utm_source=footer>
>>>> .
>>>>
>>>>
>>>> --
>>>> --Misagh
>>>>
>>>> --
>>>> - Website: https://apereo.github.io/cas
>>>> - Gitter Chatroom: https://gitter.im/apereo/cas
>>>> - List Guidelines: https://goo.gl/1VRrw7
>>>> - Contributions: https://goo.gl/mh7qDG
>>>> ---
>>>> You received this message because you are subscribed to the Google
>>>> Groups "CAS Community" group.
>>>> To unsubscribe from this group and stop receiving emails from it, send
>>>> an email to [email protected].
>>>> To view this discussion on the web visit https://groups.google.com/a/ap
>>>> ereo.org/d/msgid/cas-user/1598432640.5707319.1508431562461.
>>>> JavaMail.zimbra%40unicon.net
>>>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/1598432640.5707319.1508431562461.JavaMail.zimbra%40unicon.net?utm_medium=email&utm_source=footer>
>>>> .
>>>>
>>>
>>> --
>>> - Website: https://apereo.github.io/cas
>>> - Gitter Chatroom: https://gitter.im/apereo/cas
>>> - List Guidelines: https://goo.gl/1VRrw7
>>> - Contributions: https://goo.gl/mh7qDG
>>> ---
>>> You received this message because you are subscribed to the Google
>>> Groups "CAS Community" group.
>>> To unsubscribe from this group and stop receiving emails from it, send
>>> an email to [email protected].
>>> To view this discussion on the web visit https://groups.google.com/a/ap
>>> ereo.org/d/msgid/cas-user/CAN6MV5MpDqd-j04ykxuJ5Ae3iWz%2Bs53
>>> BLD0Wvd_ZWPAFvb1Bng%40mail.gmail.com
>>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAN6MV5MpDqd-j04ykxuJ5Ae3iWz%2Bs53BLD0Wvd_ZWPAFvb1Bng%40mail.gmail.com?utm_medium=email&utm_source=footer>
>>> .
>>>
>>>
>>> --
>>> --Misagh
>>>
>>> --
>>> - Website: https://apereo.github.io/cas
>>> - Gitter Chatroom: https://gitter.im/apereo/cas
>>> - List Guidelines: https://goo.gl/1VRrw7
>>> - Contributions: https://goo.gl/mh7qDG
>>> ---
>>> You received this message because you are subscribed to the Google
>>> Groups "CAS Community" group.
>>> To unsubscribe from this group and stop receiving emails from it, send
>>> an email to [email protected].
>>> To view this discussion on the web visit https://groups.google.com/a/ap
>>> ereo.org/d/msgid/cas-user/1396343839.5711719.1508433250798.
>>> JavaMail.zimbra%40unicon.net
>>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/1396343839.5711719.1508433250798.JavaMail.zimbra%40unicon.net?utm_medium=email&utm_source=footer>
>>> .
>>>
>>
>> --
>> - Website: https://apereo.github.io/cas
>> - Gitter Chatroom: https://gitter.im/apereo/cas
>> - List Guidelines: https://goo.gl/1VRrw7
>> - Contributions: https://goo.gl/mh7qDG
>> ---
>> You received this message because you are subscribed to the Google Groups
>> "CAS Community" group.
>> To unsubscribe from this group and stop receiving emails from it, send an
>> email to [email protected].
>> To view this discussion on the web visit https://groups.google.com/a/ap
>> ereo.org/d/msgid/cas-user/CAN6MV5NpVr1XrsJ7LUBsBEeGXy3k1RHXq
>> oEXXbkKuMEfjFCqyg%40mail.gmail.com
>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAN6MV5NpVr1XrsJ7LUBsBEeGXy3k1RHXqoEXXbkKuMEfjFCqyg%40mail.gmail.com?utm_medium=email&utm_source=footer>
>> .
>>
>> --
>> - Website: https://apereo.github.io/cas
>> - Gitter Chatroom: https://gitter.im/apereo/cas
>> - List Guidelines: https://goo.gl/1VRrw7
>> - Contributions: https://goo.gl/mh7qDG
>> ---
>> You received this message because you are subscribed to the Google Groups
>> "CAS Community" group.
>> To unsubscribe from this group and stop receiving emails from it, send an
>> email to [email protected].
>> To view this discussion on the web visit https://groups.google.com/a/ap
>> ereo.org/d/msgid/cas-user/892964821.9246869.1512522834850.
>> JavaMail.zimbra%40unicon.net
>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/892964821.9246869.1512522834850.JavaMail.zimbra%40unicon.net?utm_medium=email&utm_source=footer>
>> .
>>
>
>
--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAN6MV5PbnLATmbpR24mhcRtHSV%2BNJbtHSN07SOWRRjRbjficyg%40mail.gmail.com.