We ran into a similar issue early on with our OIDC implementation where CAS returns attributes in a "nested" format by default. We found that nearly all applications that want the userInfo payload expected the opposite so we changed the default behavior to return "flat" rather than under an "attributes" block. Cloud providers like Okta, Entra, as well as the wordpress providers all broke if we kept the default.
cas.authn.oauth.core.user-profile-view-type=FLAT On Tue, Jul 21, 2026 at 6:45 AM Vallee Romain <[email protected]> wrote: > It's ok ! > > My applications needed to receive the data in “flat” format. > Thank for all > > Le lundi 20 juillet 2026 à 15:21:53 UTC+2, Vallee Romain a écrit : > >> Thanks for your configuration file. >> >> >> I notice that the “openid” and “profile” scopes aren't returning any >> attributes. >> >> In my application-side logs, only the email address is being logged. >> >> Do I need to declare something? >> >> Le dimanche 19 juillet 2026 à 22:18:00 UTC+2, Ray Bon a écrit : >> >>> Vallee, >>> >>> Not all of the properties in the service are required. >>> There are also some custom scopes. >>> >>> Ray >>> >>> { >>> "@class": "org.apereo.cas.services.OidcRegisteredService", >>> "serviceId": "^ >>> https://democasclientlocal.uvic.ca/democasclient/callback.*[oO]idc.*", >>> "name": "Demo-OIDC", >>> "id": 10002, >>> "proxyTicketExpirationPolicy": >>> { >>> "@class": >>> "org.apereo.cas.services.DefaultRegisteredServiceProxyTicketExpirationPolicy" >>> }, >>> "serviceTicketExpirationPolicy": >>> { >>> "@class": >>> "org.apereo.cas.services.DefaultRegisteredServiceServiceTicketExpirationPolicy" >>> }, >>> "singleSignOnParticipationPolicy": { >>> "@class": >>> "org.apereo.cas.services.ChainingRegisteredServiceSingleSignOnParticipationPolicy" >>> }, >>> "evaluationOrder": 145, >>> "usernameAttributeProvider": { >>> "@class": >>> "org.apereo.cas.services.DefaultRegisteredServiceUsernameProvider", >>> "canonicalizationMode": "LOWER" >>> }, >>> "environments": null, >>> "multifactorPolicy": { >>> "@class": >>> "org.apereo.cas.services.DefaultRegisteredServiceMultifactorPolicy", >>> "multifactorAuthenticationProviders": null, >>> "bypassEnabled": true >>> }, >>> "attributeReleasePolicy": >>> { >>> "@class": "org.apereo.cas.services.DenyAllAttributeReleasePolicy" >>> }, >>> "clientSecret": "secret", >>> "clientId": "demoId", >>> "bypassApprovalPrompt": false, >>> "generateRefreshToken": true, >>> "jwtAccessToken": true, >>> "supportedGrantTypes": >>> [ >>> "java.util.HashSet", >>> [ >>> "refresh_token", >>> "password", >>> "authorization_code" >>> ] >>> ], >>> "supportedResponseTypes": >>> [ >>> "java.util.HashSet", >>> [ >>> "code", >>> "id_token", >>> "token" >>> ] >>> ], >>> "signIdToken": false, >>> "subjectType": "PUBLIC", >>> "scopes": [ >>> "java.util.HashSet", [ >>> "uvicApplications", >>> "openid", >>> "email", >>> "profile", >>> "eduPerson" >>> ] >>> ] >>> } >>> >>> ------------------------------ >>> *From:* [email protected] <[email protected]> on behalf of Vallee >>> Romain <[email protected]> >>> *Sent:* July 18, 2026 01:47 >>> *To:* CAS Community <[email protected]> >>> *Cc:* Vallee Romain <[email protected]> >>> *Subject:* [cas-user] Re: OIDC with 7.3 and code >>> >>> You don't often get email from [email protected]. Learn why this is >>> important <https://aka.ms/LearnAboutSenderIdentification> >>> Thank to @JeromeLeleu . >>> >>> Just add this : >>> >>> cas.authn.oauth.session-replication.cookie.crypto.enabled=true >>> >>> Now, i have to find how create à json service file to bring attributs to >>> application. >>> >>> Could someone provide me with an example of a JSON file that would work >>> with OIDC? One that sends attributes? >>> >>> >>> >>> Le vendredi 17 juillet 2026 à 13:32:33 UTC+2, Vallee Romain a écrit : >>> >>> Hello, >>> >>> I migrated from version 6 to latest version 7 of Jasig, and since then, >>> my services that use OIDC authentication no longer work. We're getting this >>> error message: >>> >>> Argument #2 ($code) must be of type string, null given, called in . >>> >>> I tried adapting my services using this syntax: >>> >>> root@cas7:/etc/cas/config# cat ../services/centreon-16.json >>> >>> >>> { >>> >>> “@class”: “org.apereo.cas.services.OidcRegisteredService”, >>> >>> “clientId”: “xxxxx”, >>> >>> “clientSecret”: “xxxxx”, >>> >>> “serviceId”: “ >>> http://192.168.14.159/centreon/authentication/providers/configurations/openid >>> ”, >>> >>> “evaluationOrder”: 1, >>> >>> “name”: “centreon”, >>> >>> “id”: 16, >>> >>> “bypassApprovalPrompt”: true, >>> >>> “accessStrategy”: { >>> >>> “@class”: >>> “org.apereo.cas.services.DefaultRegisteredServiceAccessStrategy”, >>> >>> “enabled”: true, >>> >>> “ssoEnabled”: true, >>> >>> “requireAllAttributes”: false, >>> >>> “requiredAttributes”: { >>> >>> “@class”: “java.util.HashMap” >>> >>> }, >>> >>> “caseInsensitive”: false >>> >>> }, >>> >>> “userProfileViewType”: “FLAT”, >>> >>> “supportedGrantTypes”: [“java.util.HashSet”, [“authorization_code”]], >>> >>> “supportedResponseTypes”: [“java.util.HashSet”, [“code”]], >>> >>> “scopes”: [“java.util.HashSet”, >>> [“openid”,“profile”,“email”,‘groups’,“roles”]], >>> >>> “includeClaimsInIdToken”: true >>> >>> } >>> >>> >>> The logs don't show anything unusual. >>> >>> >>> Have you ever encountered this problem? >>> >>> >>> Thank you >>> >>> Best regards >>> >>> -- >>> - Website: https://apereo.github.io/cas >>> - List Guidelines: https://goo.gl/1VRrw7 >>> - Contributions: https://goo.gl/mh7qDG >>> --- >>> You received this message because you are subscribed to the Google >>> Groups "CAS Community" group. >>> To unsubscribe from this group and stop receiving emails from it, send >>> an email to [email protected]. >>> To view this discussion visit >>> https://groups.google.com/a/apereo.org/d/msgid/cas-user/c45ceb63-1a05-4e22-a608-8e62519fc514n%40apereo.org >>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/c45ceb63-1a05-4e22-a608-8e62519fc514n%40apereo.org?utm_medium=email&utm_source=footer> >>> . >>> >> -- > - Website: https://apereo.github.io/cas > - List Guidelines: https://goo.gl/1VRrw7 > - Contributions: https://goo.gl/mh7qDG > --- > You received this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > To view this discussion visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/eae0c4f9-7dd3-4e18-ba4f-0b465407b4ean%40apereo.org > <https://groups.google.com/a/apereo.org/d/msgid/cas-user/eae0c4f9-7dd3-4e18-ba4f-0b465407b4ean%40apereo.org?utm_medium=email&utm_source=footer> > . > -- Jonathon Taylor Information Security Office | University of California, Berkeley [email protected] -- - Website: https://apereo.github.io/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/CABzqDo9eRbanvEBeHHAOARH8Ee2PcFFa6LA7NCghUnyTrPT1vg%40mail.gmail.com.
