Hello, I’m currently migrating a CAS server from version 6.6.15 to 7.3.5.
In CAS 6.6.15, we were using actuator endpoints to: - list registered services via: /cas/actuator/registeredServices - import services via: POST /cas/actuator/registeredServices/import This was working fine with basic properties configuration. After upgrading to CAS 7.3.5, I’m facing a consistent HTTP 403 (Forbidden) on: /cas/actuator/registeredServices Context: - Spring Boot 3 / Spring Security 6 - Using basic auth with: spring.security.user.name spring.security.user.password spring.security.user.roles=ACTUATOR Configuration includes: - management.endpoints.web.exposure.include=* - cas.monitor.endpoints.endpoint.defaults.access=PERMIT - cas.monitor.endpoints.endpoint.registeredServices.access=PERMIT Despite that: - Browser access → 403 - curl with -u → 403 Questions: 1. Is access to /actuator/registeredServices now restricted by default in CAS 7? 2. Is additional Spring Security configuration required (beyond properties)? 3. Is the import endpoint still supported in CAS 7.3.5? Thanks in advance for your help. -- - Website: https://apereo.github.io/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/731049ff-becd-42ed-bcc5-6ae5cff88b83n%40apereo.org.
