Hello Ray,
Thank you for your help. Yes, after turning on debugging, I found that you
were correct, _isLogoutRequest handles "single logout" requests coming from
CAS.
However, as far as: $client_ip = $_SERVER['REMOTE_ADDR'];
I think there is a bug/oversight in the Client.php code if the app is
behind a load balancer.
*config.php*
--------------
$cas_real_hosts = array('cas-real-1.example.com', 'cas-real-2.example.com');
.
.
.
phpCAS::handleLogoutRequests(true, $cas_real_hosts);
*Client.php*
--------------
.
.
.
public function handleLogoutRequests($check_client=true, $allowed_clients
=array())
.
.
.
if ($check_client) {
if ($allowed_clients === array()) {
$allowed_clients = array( $this->_getServerHostname() );
}
$client_ip = $_SERVER['REMOTE_ADDR'];
$client = gethostbyaddr($client_ip);
phpCAS::trace("Client: ".$client."/".$client_ip);
foreach ($allowed_clients as $allowed_client) {
if (($client == $allowed_client)
|| ($client_ip == $allowed_client)
) {
phpCAS::trace(
"Allowed client '".$allowed_client
."' matches, logout request is allowed"
);
$allowed = true;
break;
} else {
phpCAS::trace(
"Allowed client '".$allowed_client."' does not match"
);
}
}
}
The $client_ip will be set to the load balancer's IP address, then $client
(the host name) will be set via $client_ip, which will also return the load
balancer's hostname. So then when it checks if the $client (the hostname)
is in the list of $allowed_clients (which can be configured via
config.php's $cas_real_hosts = array('cas-real-1.example.com', '
cas-real-2.example.com'); ) it won't match. Even if I were to set the
$allowed clients (again via $cas_real_hosts) to IP addresses, that still
won't work because again, $_SERVER['REMOTE_ADDR'] returns the load
balancer's IP. I think instead of setting $client_ip =
$_SERVER['REMOTE_ADDR'];, it should check the various x-forwarded-for, etc.
address I mentioned in my first email... or am I misunderstanding the code?
Thanks,
Austin
On Fri, Jun 14, 2019 at 10:16 AM Ray Bon <[email protected]> wrote:
> Austin,
>
> You can turn on debugging in the phpCAS client to get a _very_ detailed
> account of what is happening.
>
> The code in the if block only runs if it is not a log out request. I do
> not remember the exact bits in phpCAS, but is it possible that
> _isLogoutRequest performs the log out?
>
> _isLogoutRequest handles requests coming from CAS, not the one you are
> sending to CAS by clicking the logout button in your php app (which is what
> you observed).
>
> #2 I suppose it depends on what $client_ip is used for.
>
> You can check correct log out behaviour by visiting cas/logout in a new
> tab.
>
> Ray
>
> On Fri, 2019-06-14 at 10:00 -1000, Austin wrote:
>
> Hello CAS developers,
>
> I have a couple of questions about logout requests behind a load balancer.
>
> 1) In Client.php
>
> public function handleLogoutRequests($check_client=true,
> $allowed_clients=array())
> {
> phpCAS::traceBegin();
> if (!$this->_isLogoutRequest()) {
> phpCAS::trace("Not a logout request");
> phpCAS::traceEnd();
> return;
> }
>
> I'm calling phpCAS::logoutWithRedirectService($logout_url);
> but the function above never gets past the line
>
> if (!$this->_isLogoutRequest()) {
>
> even though I would have though that logoutWithRedirectService() is a
> logout request? However, my app still does appear to logout from CAS (I
> can see the log request go out to our CAS server), but I was just wondering
> if/why my request isn't a _isLogoutRequest(). Or is it ok that the rest of
> the code in that function is never run?
>
> 2) Also in Client.php
>
> in the same function above, further down in the code, there's a line
>
> $client_ip = $_SERVER['REMOTE_ADDR'];
>
> If my app (ever gets to that line (see #1 above)) is behind a load
> balancer, wouldn't that line NOT be reliable? should it also be checking for
>
> HTTP_CLIENT_IP
> HTTP_X_FORWARDED_FOR
> HTTP_X_FORWARDED
> HTTP_X_FORWARDED
> HTTP_FORWARDED_FOR
> HTTP_FORWARDED
> REMOTE_ADDR
>
>
> https://stackoverflow.com/questions/44085102/php-most-accurate-safe-way-to-get-real-user-ip-address-in-2017
>
> --
>
> Ray Bon
> Programmer Analyst
> Development Services, University Systems
> 2507218831 | CLE 019 | [email protected]
>
> I respectfully acknowledge that my place of work is located within the
> ancestral, traditional and unceded territory of the Songhees, Esquimalt and
> WSÁNEĆ Nations.
>
> --
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit
> https://groups.google.com/a/apereo.org/d/msgid/cas-user/e21790104c48aa795dcb04d4f074f1f4909f8d4b.camel%40uvic.ca
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/e21790104c48aa795dcb04d4f074f1f4909f8d4b.camel%40uvic.ca?utm_medium=email&utm_source=footer>
> .
>
--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAKL84%3DmnLNgMk6zf-r_-eBQZPif%2BRuj7PY34H085fx6SFG129w%40mail.gmail.com.