Hello,

I’m currently migrating a CAS server from version 6.6.15 to 7.3.5.

In CAS 6.6.15, we were using actuator endpoints to:
- list registered services via:
  /cas/actuator/registeredServices
- import services via:
  POST /cas/actuator/registeredServices/import

This was working fine with basic properties configuration.

After upgrading to CAS 7.3.5, I’m facing a consistent HTTP 403 (Forbidden) 
on:
  /cas/actuator/registeredServices

Context:
- Spring Boot 3 / Spring Security 6
- Using basic auth with:
  spring.security.user.name
  spring.security.user.password
  spring.security.user.roles=ACTUATOR

Configuration includes:
- management.endpoints.web.exposure.include=*
- cas.monitor.endpoints.endpoint.defaults.access=PERMIT
- cas.monitor.endpoints.endpoint.registeredServices.access=PERMIT

Despite that:
- Browser access → 403
- curl with -u → 403

Questions:
1. Is access to /actuator/registeredServices now restricted by default in 
CAS 7?
2. Is additional Spring Security configuration required (beyond properties)?
3. Is the import endpoint still supported in CAS 7.3.5?

Thanks in advance for your help.

-- 
- Website: https://apereo.github.io/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/731049ff-becd-42ed-bcc5-6ae5cff88b83n%40apereo.org.

Reply via email to