[cas-user] CAS 6.6.x OAuth2 profile endpoint releases all authentication attributes

2023-04-27 Thread Marie Schaeffer
With CAS 6.6.x (current tests were with the CAS 6.6.6 and 6.6.7 overlay) I get from the OAuth endpoint oauth2.0/profile all the authentication attributes in addition to the attributes that should be released according to the attributeReleasePolicy in the service definition. Unwanted parts of pr

Re: [cas-user] Error "403 Forbidden" on "CAS management => Administration => Release Attributes" (CAS server 665 + CAS management 662)

2023-04-27 Thread Luís Costa
Hello Ray, Thank you for you answer, I'm sorry for the delay in replying. >> >> Luis >> >> if I try to call the actuator like this (don't know if it's the right way), >> >> >> >> https://localhost:8443/cas/actuator/releaseAttributes?username=ABExyz&password=somepassword&service=ca

Re: [cas-user] Error "403 Forbidden" on "CAS management => Administration => Release Attributes" (CAS server 665 + CAS management 662)

2023-04-27 Thread Ray Bon
Luís, I, too, expect that cas management will get some of its config from cas. I have not yet tested that and have attributes listed in both properties files. I am not sure whether a POST or GET should be used. One thing to consider is your certificates for https. If you are using self signed ce