diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index 0f7628b27..1670cb60e 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -24,52 +24,3 @@ updates:
schedule:
interval: daily
open-pull-requests-limit: 10
- ignore:
- - dependency-name: org.springframework.boot:spring-boot-dependencies
- versions:
- - 2.4.4
- - dependency-name: org.springframework:spring-beans
- versions:
- - 5.3.5
- - dependency-name: org.springframework:spring-test
- versions:
- - 5.3.5
- - dependency-name: org.springframework:spring-web
- versions:
- - 5.3.5
- - dependency-name: org.springframework:spring-context
- versions:
- - 5.3.5
- - dependency-name: org.springframework:spring-core
- versions:
- - 5.3.5
- - dependency-name: org.apache.tomcat.embed:tomcat-embed-core
- versions:
- - 10.0.0
- - 10.0.2
- - 10.0.4
- - dependency-name: org.apache.tomcat:tomcat-catalina
- versions:
- - 10.0.0
- - 10.0.2
- - 10.0.4
- - dependency-name: org.eclipse.jetty:apache-jsp
- versions:
- - 11.0.0
- - 11.0.1
- - dependency-name: org.eclipse.jetty:jetty-annotations
- versions:
- - 11.0.0
- - 11.0.1
- - dependency-name: org.eclipse.jetty:jetty-plus
- versions:
- - 11.0.0
- - 11.0.1
- - dependency-name: org.eclipse.jetty:jetty-webapp
- versions:
- - 11.0.0
- - 11.0.1
- - dependency-name: org.eclipse.jetty:jetty-security
- versions:
- - 11.0.0
- - 11.0.1
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
index a6b964923..25303d615 100644
--- a/.github/workflows/build.yml
+++ b/.github/workflows/build.yml
@@ -27,7 +27,7 @@ env:
SONATYPE_USER: ${{ secrets.SONATYPE_USER }}
GH_TOKEN: ${{ secrets.GH_PAGES_TOKEN }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- JDK_CURRENT: 8
+ JDK_CURRENT: 21
##########################################################################
@@ -44,7 +44,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 1
steps:
- - uses: styfle/cancel-workflow-action@0.7.0
+ - uses: styfle/cancel-workflow-action@0.13.1
with:
access_token: ${{ github.token }}
build:
@@ -55,13 +55,14 @@ jobs:
runs-on: ${{ matrix.os }}
needs: cancel-previous-runs
steps:
- - uses: actions/checkout@v2
+ - uses: actions/checkout@v7
# - name: Setup tmate session
# uses: mxschmitt/action-tmate@v3
- name: Set up JDK
- uses: actions/setup-java@v1
+ uses: actions/setup-java@v5
with:
java-version: ${{ env.JDK_CURRENT }}
+ distribution: 'temurin'
- name: Build with Gradle
run: mvn clean install
@@ -72,11 +73,12 @@ jobs:
needs: [build]
if: ${{ github.event_name == 'push' }}
steps:
- - uses: actions/checkout@v2
+ - uses: actions/checkout@v7
- name: Set up JDK
- uses: actions/setup-java@v1
+ uses: actions/setup-java@v5
with:
java-version: ${{ env.JDK_CURRENT }}
+ distribution: 'temurin'
- name: Publish SNAPSHOTs
if: ${{ env.SONATYPE_USER != null && env.SONATYPE_PWD != null }}
run: mvn deploy --settings ./.github/workflows/settings.xml
diff --git a/.mergify.yml b/.mergify.yml
index 2f71fe38e..f9be0951e 100644
--- a/.mergify.yml
+++ b/.mergify.yml
@@ -1,32 +1,12 @@
-#
-# Licensed to Apereo under one or more contributor license
-# agreements. See the NOTICE file distributed with this work
-# for additional information regarding copyright ownership.
-# Apereo licenses this file to you under the Apache License,
-# Version 2.0 (the "License"); you may not use this file
-# except in compliance with the License. You may obtain a
-# copy of the License at the following location:
-#
-# http://www.apache.org/licenses/LICENSE-2.0
-#
-# Unless required by applicable law or agreed to in writing,
-# software distributed under the License is distributed on an
-# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
-# KIND, either express or implied. See the License for the
-# specific language governing permissions and limitations
-# under the License.
-#
-
pull_request_rules:
-- name: automatic merge
- conditions:
- - status-success=build (ubuntu-latest)
- - status-success=WIP
- - "#changes-requested-reviews-by=0"
- - base=master
- - label=dependencies
- actions:
- merge:
- method: merge
- strict: false
- delete_head_branch:
\ No newline at end of file
+ - name: automatic merge
+ conditions:
+ - status-success=build (ubuntu-latest)
+ - status-success=WIP
+ - "#changes-requested-reviews-by=0"
+ - base=master
+ - label=dependencies
+ actions:
+ merge:
+ method: merge
+ update:
diff --git a/.travis.yml b/.travis.yml
deleted file mode 100644
index ed6686943..000000000
--- a/.travis.yml
+++ /dev/null
@@ -1,38 +0,0 @@
-#
-# Licensed to Jasig under one or more contributor license
-# agreements. See the NOTICE file distributed with this work
-# for additional information regarding copyright ownership.
-# Jasig licenses this file to you under the Apache License,
-# Version 2.0 (the "License"); you may not use this file
-# except in compliance with the License. You may obtain a
-# copy of the License at the following location:
-#
-# http://www.apache.org/licenses/LICENSE-2.0
-#
-# Unless required by applicable law or agreed to in writing,
-# software distributed under the License is distributed on an
-# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
-# KIND, either express or implied. See the License for the
-# specific language governing permissions and limitations
-# under the License.
-#
-
-language: java
-sudo: required
-branches:
- only:
- - master
-cache:
- directories:
- - "$HOME/.m2/repository"
-script: "mvn install --settings travis/settings.xml"
-jdk:
- - openjdk8
-env:
- global:
- - secure: "JM/FMiec3GYShrMlJQSW2QG208+V0GCAj2bsP5eF8q4yzgp6o4rT+r57KDIDD6MapRN+G1Pnl3WPcS0aQYnwOhPg4tA2De1bFUPaJltP47eHFfblpjZeHMxcauCQ6BwFFr8yuC0ORsYCW3TOK00Mxq4CRlTlg5iclzHyS/pnkLI="
- - secure: "eXfgf3v8Kw/L22DO39Y61os13bfNpop8Xpkmz+HZ1djQWavOkRn58gSg8EVjBYRPOrTuEbhEWb+s3qpx8j3qRdi6roMs9MTr5gEPTAyjTtJ/Zv1qhJ6OlEl2w5c2fRMsk5cB//mtxtZ+qMaz6sdZI2csbQ2xlhjz4AbGQL5i1lY="
-
-after_success:
-- chmod -R 777 ./travis/deploy-to-sonatype.sh
-- ./travis/deploy-to-sonatype.sh
diff --git a/LICENSE b/LICENSE
index eef349383..52eeacd65 100644
--- a/LICENSE
+++ b/LICENSE
@@ -1,8 +1,8 @@
====
- Licensed to Jasig under one or more contributor license
+ Licensed to Apereo under one or more contributor license
agreements. See the NOTICE file distributed with this work
for additional information regarding copyright ownership.
- Jasig licenses this file to you under the Apache License,
+ Apereo licenses this file to you under the Apache License,
Version 2.0 (the "License"); you may not use this file
except in compliance with the License. You may obtain a
copy of the License at:
@@ -47,4 +47,4 @@ PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
-SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
\ No newline at end of file
+SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
diff --git a/NOTICE b/NOTICE
index 052663a24..c5b762607 100644
--- a/NOTICE
+++ b/NOTICE
@@ -40,19 +40,19 @@ This project includes:
Jackson-core under The Apache Software License, Version 2.0
jackson-databind under The Apache Software License, Version 2.0
Jakarta Annotations API under EPL 2.0 or GPL2 w/ CPE
- Jasig CAS Client for Java - Common Tomcat Integration Support under Apache License Version 2.0
- Jasig CAS Client for Java - Core under Apache License Version 2.0
- Jasig CAS Client for Java - Distributed Proxy Storage Support: EhCache under Apache License Version 2.0
- Jasig CAS Client for Java - Distributed Proxy Storage Support: Memcached under Apache License Version 2.0
- Jasig CAS Client for Java - JBoss Integration under Apache License Version 2.0
- Jasig CAS Client for Java - Jetty Container Integration under Apache License Version 2.0
- Jasig CAS Client for Java - SAML Protocol Support under Apache License Version 2.0
- Jasig CAS Client for Java - Spring Boot Support under Apache License Version 2.0
- Jasig CAS Client for Java - Tomcat 6.x Integration under Apache License Version 2.0
- Jasig CAS Client for Java - Tomcat 7.x Integration under Apache License Version 2.0
- Jasig CAS Client for Java - Tomcat 8.5.x Integration under Apache License Version 2.0
- Jasig CAS Client for Java - Tomcat 8.x Integration under Apache License Version 2.0
- Jasig CAS Client for Java - Tomcat 9.0.x Integration under Apache License Version 2.0
+ Apereo CAS Client for Java - Common Tomcat Integration Support under Apache License Version 2.0
+ Apereo CAS Client for Java - Core under Apache License Version 2.0
+ Apereo CAS Client for Java - Distributed Proxy Storage Support: EhCache under Apache License Version 2.0
+ Apereo CAS Client for Java - Distributed Proxy Storage Support: Memcached under Apache License Version 2.0
+ Apereo CAS Client for Java - JBoss Integration under Apache License Version 2.0
+ Apereo CAS Client for Java - Jetty Container Integration under Apache License Version 2.0
+ Apereo CAS Client for Java - SAML Protocol Support under Apache License Version 2.0
+ Apereo CAS Client for Java - Spring Boot Support under Apache License Version 2.0
+ Apereo CAS Client for Java - Tomcat 6.x Integration under Apache License Version 2.0
+ Apereo CAS Client for Java - Tomcat 7.x Integration under Apache License Version 2.0
+ Apereo CAS Client for Java - Tomcat 8.5.x Integration under Apache License Version 2.0
+ Apereo CAS Client for Java - Tomcat 8.x Integration under Apache License Version 2.0
+ Apereo CAS Client for Java - Tomcat 9.0.x Integration under Apache License Version 2.0
Java Servlet API under CDDL + GPLv2 with classpath exception
JavaBeans Activation Framework API jar under CDDL/GPLv2+CE
javax.annotation API under CDDL + GPLv2 with classpath exception
@@ -74,7 +74,6 @@ This project includes:
Jetty :: Utilities :: Ajax(JSON) under Apache Software License - Version 2.0 or Eclipse Public License - Version 1.0
Jetty :: Webapp Application Support under Apache Software License - Version 2.0 or Eclipse Public License - Version 1.0
Jetty :: XML utilities under Apache Software License - Version 2.0 or Eclipse Public License - Version 1.0
- Joda-Time under Apache License, Version 2.0
JUL to SLF4J bridge under MIT License
JUnit under Eclipse Public License 1.0
Logback Classic Module under Eclipse Public License - v 1.0 or GNU Lesser General Public License
diff --git a/README.md b/README.md
index af86b9447..f2d4904b6 100644
--- a/README.md
+++ b/README.md
@@ -1,4 +1,4 @@
-# Java Apereo CAS Client [](https://maven-badges.herokuapp.com/maven-central/org.jasig.cas.client/cas-client)
+# Java Apereo CAS Client
## Intro
@@ -7,7 +7,7 @@ This is the official home of the Java Apereo CAS client. The client consists of
All client artifacts are published to Maven central. Depending on functionality, applications will need include one or more of the listed dependencies in their configuration.
-## Build [](https://travis-ci.org/apereo/java-cas-client)
+## Build
```bash
git clone git@github.com:apereo/java-cas-client.git
@@ -15,9 +15,6 @@ cd java-cas-client
mvn clean package
```
-Please note that to be deployed in Maven Central, we mark a number of JARs as provided (related to JBoss and Memcache
-Clients). In order to build the clients, you must enable the commented out repositories in the appropriate `pom.xml`
-files in the modules (`cas-client-integration-jboss` and `cas-client-support-distributed-memcached`) or follow the instructions on how to install the file manually.
## Components
@@ -26,7 +23,7 @@ files in the modules (`cas-client-integration-jboss` and `cas-client-support-dis
```xml
- org.jasig.cas.client
+ org.apereo.cas.clientcas-client-core${java.cas.client.version}
@@ -36,7 +33,7 @@ files in the modules (`cas-client-integration-jboss` and `cas-client-support-dis
```xml
- org.jasig.cas.client
+ org.apereo.cas.clientcas-client-support-saml${java.cas.client.version}
@@ -46,7 +43,7 @@ files in the modules (`cas-client-integration-jboss` and `cas-client-support-dis
```xml
- org.jasig.cas.client
+ org.apereo.cas.clientcas-client-support-distributed-ehcache${java.cas.client.version}
@@ -56,87 +53,17 @@ files in the modules (`cas-client-integration-jboss` and `cas-client-support-dis
```xml
- org.jasig.cas.client
+ org.apereo.cas.clientcas-client-support-distributed-memcached${java.cas.client.version}
```
-- Atlassian integration (Deprecated) is provided by this dependency:
-
-```xml
-
- org.jasig.cas.client
- cas-client-integration-atlassian
- ${java.cas.client.version}
-
-```
-
-- JBoss integration is provided by this dependency:
-
-```xml
-
- org.jasig.cas.client
- cas-client-integration-jboss
- ${java.cas.client.version}
-
-```
-
-- Tomcat 6 integration is provided by this dependency:
-
-```xml
-
- org.jasig.cas.client
- cas-client-integration-tomcat-v6
- ${java.cas.client.version}
-
-```
-
-- Tomcat 7 is provided by this dependency:
-
-```xml
-
- org.jasig.cas.client
- cas-client-integration-tomcat-v7
- ${java.cas.client.version}
-
-```
-
-- Tomcat 8.0.x is provided by this dependency:
-
-```xml
-
- org.jasig.cas.client
- cas-client-integration-tomcat-v8
- ${java.cas.client.version}
-
-```
-
-- Tomcat 8.5.x is provided by this dependency:
-
-```xml
-
- org.jasig.cas.client
- cas-client-integration-tomcat-v85
- ${java.cas.client.version}
-
-```
-
-- Tomcat 9.0.x is provided by this dependency:
-
-```xml
-
- org.jasig.cas.client
- cas-client-integration-tomcat-v90
- ${java.cas.client.version}
-
-```
-
- Spring Boot AutoConfiguration is provided by this dependency:
```xml
- org.jasig.cas.client
+ org.apereo.cas.clientcas-client-support-springboot${java.cas.client.version}
@@ -187,14 +114,14 @@ The client can be configured in `web.xml` via a series of `context-param`s and f
An example application that is protected by the client is [available here](https://github.com/UniconLabs/cas-sample-java-webapp).
-
-#### org.jasig.cas.client.authentication.AuthenticationFilter
+
+#### org.apereo.cas.client.authentication.AuthenticationFilter
The `AuthenticationFilter` is what detects whether a user needs to be authenticated or not. If a user needs to be authenticated, it will redirect the user to the CAS server.
```xml
CAS Authentication Filter
- org.jasig.cas.client.authentication.AuthenticationFilter
+ org.apereo.cas.client.authentication.AuthenticationFiltercasServerUrlPrefixhttps://battags.ad.ess.rutgers.edu:8443/cas
@@ -210,43 +137,42 @@ The `AuthenticationFilter` is what detects whether a user needs to be authentica
```
-| Property | Description | Required
-|----------|-------|-----------
-| `casServerUrlPrefix` | The start of the CAS server URL, i.e. `https://localhost:8443/cas` | Yes (unless `casServerLoginUrl` is set)
-| `casServerLoginUrl` | Defines the location of the CAS server login URL, i.e. `https://localhost:8443/cas/login`. This overrides `casServerUrlPrefix`, if set. | Yes (unless `casServerUrlPrefix` is set)
-| `serverName` | The name of the server this application is hosted on. Service URL will be dynamically constructed using this, i.e. https://localhost:8443 (you must include the protocol, but port is optional if it's a standard port). | Yes
-| `service` | The service URL to send to the CAS server, i.e. `https://localhost:8443/yourwebapp/index.html` | No
-| `renew` | specifies whether `renew=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all). Note that `renew` cannot be specified as local `init-param` setting. | No
-| `gateway ` | specifies whether `gateway=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all) | No
-| `artifactParameterName ` | specifies the name of the request parameter on where to find the artifact (i.e. `ticket`). | No
-| `serviceParameterName ` | specifies the name of the request parameter on where to find the service (i.e. `service`) | No
-| `encodeServiceUrl ` | Whether the client should auto encode the service url. Defaults to `true` | No
-| `ignorePattern` | Defines the url pattern to ignore, when intercepting authentication requests. | No
-| `ignoreUrlPatternType` | Defines the type of the pattern specified. Defaults to `REGEX`. Other types are `CONTAINS`, `EXACT`, `FULL_REGEX`. Can also accept a fully-qualified class name that implements `UrlPatternMatcherStrategy`. | No
-| `gatewayStorageClass` | The storage class used to record gateway requests | No
-| `authenticationRedirectStrategyClass` | The class name of the component to decide how to handle authn redirects to CAS | No
-| `method` | The method used by the CAS server to send the user back to the application. Defaults to `null` | No
+| Property | Description | Required |
+|---------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------|
+| `casServerUrlPrefix` | The start of the CAS server URL, i.e. `https://localhost:8443/cas` | Yes (unless `casServerLoginUrl` is set) |
+| `casServerLoginUrl` | Defines the location of the CAS server login URL, i.e. `https://localhost:8443/cas/login`. This overrides `casServerUrlPrefix`, if set. | Yes (unless `casServerUrlPrefix` is set) |
+| `serverName` | The name of the server this application is hosted on. Service URL will be dynamically constructed using this, i.e. https://localhost:8443 (you must include the protocol, but port is optional if it's a standard port). | Yes |
+| `service` | The service URL to send to the CAS server, i.e. `https://localhost:8443/yourwebapp/index.html` | No |
+| `renew` | specifies whether `renew=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all). Note that `renew` cannot be specified as local `init-param` setting. | No |
+| `gateway ` | specifies whether `gateway=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all) | No |
+| `artifactParameterName ` | specifies the name of the request parameter on where to find the artifact (i.e. `ticket`). | No |
+| `serviceParameterName ` | specifies the name of the request parameter on where to find the service (i.e. `service`) | No |
+| `encodeServiceUrl ` | Whether the client should auto encode the service url. Defaults to `true` | No |
+| `ignorePattern` | Defines the url pattern to ignore, when intercepting authentication requests. | No |
+| `ignoreUrlPatternType` | Defines the type of the pattern specified. Defaults to `REGEX`. Other types are `CONTAINS`, `EXACT`, `FULL_REGEX`. Can also accept a fully-qualified class name that implements `UrlPatternMatcherStrategy`. | No |
+| `gatewayStorageClass` | The storage class used to record gateway requests | No |
+| `authenticationRedirectStrategyClass` | The class name of the component to decide how to handle authn redirects to CAS | No |
+| `method` | The method used by the CAS server to send the user back to the application. Defaults to `null` | No |
##### Ignore Patterns
The following types are supported:
-| Type | Description
-|----------|-------
-| `REGEX` | Matches the URL the `ignorePattern` using `Matcher#find()`. It matches the next occurrence within the substring that matches the regex.
-| `CONTAINS` | Uses the `String#contains()` operation to determine if the url contains the specified pattern. Behavior is case-sensitive.
-| `EXACT` | Uses the `String#equals()` operation to determine if the url exactly equals the specified pattern. Behavior is case-sensitive.
-| `FULL_REGEX` | Matches the URL the `ignorePattern` using `Matcher#matches()`. It matches the expression against the entire string as it implicitly add a `^` at the start and `$` at the end of the pattern, so it will not match substring or part of the string. `^` and `$` are meta characters that represents start of the string and end of the string respectively.
+| Type | Description |
+|--------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
+| `REGEX` | Matches the URL the `ignorePattern` using `Matcher#find()`. It matches the next occurrence within the substring that matches the regex. |
+| `CONTAINS` | Uses the `String#contains()` operation to determine if the url contains the specified pattern. Behavior is case-sensitive. |
+| `EXACT` | Uses the `String#equals()` operation to determine if the url exactly equals the specified pattern. Behavior is case-sensitive. |
+| `FULL_REGEX` | Matches the URL the `ignorePattern` using `Matcher#matches()`. It matches the expression against the entire string as it implicitly add a `^` at the start and `$` at the end of the pattern, so it will not match substring or part of the string. `^` and `$` are meta characters that represents start of the string and end of the string respectively. |
-
-
-#### org.jasig.cas.client.authentication.Saml11AuthenticationFilter
+
+#### org.apereo.cas.client.authentication.Saml11AuthenticationFilter
The SAML 1.1 `AuthenticationFilter` is what detects whether a user needs to be authenticated or not. If a user needs to be authenticated, it will redirect the user to the CAS server.
```xml
CAS Authentication Filter
- org.jasig.cas.client.authentication.Saml11AuthenticationFilter
+ org.apereo.cas.client.authentication.Saml11AuthenticationFiltercasServerLoginUrlhttps://somewhere.cas.edu:8443/cas/login
@@ -262,27 +188,27 @@ The SAML 1.1 `AuthenticationFilter` is what detects whether a user needs to be a
```
-| Property | Description | Required
-|----------|-------|-----------
-| `casServerUrlPrefix` | The start of the CAS server URL, i.e. `https://localhost:8443/cas` | Yes (unless `casServerLoginUrl` is set)
-| `casServerLoginUrl` | Defines the location of the CAS server login URL, i.e. `https://localhost:8443/cas/login`. This overrides `casServerUrlPrefix`, if set. | Yes (unless `casServerUrlPrefix` is set)
-| `serverName` | The name of the server this application is hosted on. Service URL will be dynamically constructed using this, i.e. https://localhost:8443 (you must include the protocol, but port is optional if it's a standard port). | Yes
-| `service` | The service URL to send to the CAS server, i.e. `https://localhost:8443/yourwebapp/index.html` | No
-| `renew` | specifies whether `renew=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all). Note that `renew` cannot be specified as local `init-param` setting. | No
-| `gateway ` | specifies whether `gateway=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all) | No
-| `artifactParameterName ` | specifies the name of the request parameter on where to find the artifact (i.e. `SAMLart`). | No
-| `serviceParameterName ` | specifies the name of the request parameter on where to find the service (i.e. `TARGET`) | No
-| `encodeServiceUrl ` | Whether the client should auto encode the service url. Defaults to `true` | No
-| `method` | The method used by the CAS server to send the user back to the application. Defaults to `null` | No
-
-
-#### org.jasig.cas.client.validation.Cas10TicketValidationFilter
+| Property | Description | Required |
+|--------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------|
+| `casServerUrlPrefix` | The start of the CAS server URL, i.e. `https://localhost:8443/cas` | Yes (unless `casServerLoginUrl` is set) |
+| `casServerLoginUrl` | Defines the location of the CAS server login URL, i.e. `https://localhost:8443/cas/login`. This overrides `casServerUrlPrefix`, if set. | Yes (unless `casServerUrlPrefix` is set) |
+| `serverName` | The name of the server this application is hosted on. Service URL will be dynamically constructed using this, i.e. https://localhost:8443 (you must include the protocol, but port is optional if it's a standard port). | Yes |
+| `service` | The service URL to send to the CAS server, i.e. `https://localhost:8443/yourwebapp/index.html` | No |
+| `renew` | specifies whether `renew=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all). Note that `renew` cannot be specified as local `init-param` setting. | No |
+| `gateway ` | specifies whether `gateway=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all) | No |
+| `artifactParameterName ` | specifies the name of the request parameter on where to find the artifact (i.e. `SAMLart`). | No |
+| `serviceParameterName ` | specifies the name of the request parameter on where to find the service (i.e. `TARGET`) | No |
+| `encodeServiceUrl ` | Whether the client should auto encode the service url. Defaults to `true` | No |
+| `method` | The method used by the CAS server to send the user back to the application. Defaults to `null` | No |
+
+
+#### org.apereo.cas.client.validation.Cas10TicketValidationFilter
Validates tickets using the CAS 1.0 Protocol.
```xml
CAS Validation Filter
- org.jasig.cas.client.validation.Cas10TicketValidationFilter
+ org.apereo.cas.client.validation.Cas10TicketValidationFiltercasServerUrlPrefixhttps://somewhere.cas.edu:8443/cas
@@ -298,26 +224,26 @@ Validates tickets using the CAS 1.0 Protocol.
```
-| Property | Description | Required
-|----------|-------|-----------
-| `casServerUrlPrefix ` | The start of the CAS server URL, i.e. `https://localhost:8443/cas` | Yes
-| `serverName` | The name of the server this application is hosted on. Service URL will be dynamically constructed using this, i.e. `https://localhost:8443` (you must include the protocol, but port is optional if it's a standard port). | Yes
-| `renew` | Specifies whether `renew=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all). Note that `renew` cannot be specified as local `init-param` setting. | No
-| `redirectAfterValidation ` | Whether to redirect to the same URL after ticket validation, but without the ticket in the parameter. Defaults to `true`. | No
-| `useSession ` | Whether to store the Assertion in session or not. If sessions are not used, tickets will be required for each request. Defaults to `true`. | No
-| `exceptionOnValidationFailure ` | Whether to throw an exception or not on ticket validation failure. Defaults to `true`. | No
-| `sslConfigFile` | A reference to a properties file that includes SSL settings for client-side SSL config, used during back-channel calls. The configuration includes keys for `protocol` which defaults to `SSL`, `keyStoreType`, `keyStorePath`, `keyStorePass`, `keyManagerType` which defaults to `SunX509` and `certificatePassword`. | No.
-| `encoding` | Specifies the encoding charset the client should use | No
-| `hostnameVerifier` | Hostname verifier class name, used when making back-channel calls | No
-
-
-#### org.jasig.cas.client.validation.Saml11TicketValidationFilter
+| Property | Description | Required |
+|---------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------|
+| `casServerUrlPrefix ` | The start of the CAS server URL, i.e. `https://localhost:8443/cas` | Yes |
+| `serverName` | The name of the server this application is hosted on. Service URL will be dynamically constructed using this, i.e. `https://localhost:8443` (you must include the protocol, but port is optional if it's a standard port). | Yes |
+| `renew` | Specifies whether `renew=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all). Note that `renew` cannot be specified as local `init-param` setting. | No |
+| `redirectAfterValidation ` | Whether to redirect to the same URL after ticket validation, but without the ticket in the parameter. Defaults to `true`. | No |
+| `useSession ` | Whether to store the Assertion in session or not. If sessions are not used, tickets will be required for each request. Defaults to `true`. | No |
+| `exceptionOnValidationFailure ` | Whether to throw an exception or not on ticket validation failure. Defaults to `true`. | No |
+| `sslConfigFile` | A reference to a properties file that includes SSL settings for client-side SSL config, used during back-channel calls. The configuration includes keys for `protocol` which defaults to `SSL`, `keyStoreType`, `keyStorePath`, `keyStorePass`, `keyManagerType` which defaults to `SunX509` and `certificatePassword`. | No. |
+| `encoding` | Specifies the encoding charset the client should use | No |
+| `hostnameVerifier` | Hostname verifier class name, used when making back-channel calls | No |
+
+
+#### org.apereo.cas.client.validation.Saml11TicketValidationFilter
Validates tickets using the SAML 1.1 protocol.
```xml
CAS Validation Filter
- org.jasig.cas.client.validation.Saml11TicketValidationFilter
+ org.apereo.cas.client.validation.Saml11TicketValidationFiltercasServerUrlPrefixhttps://battags.ad.ess.rutgers.edu:8443/cas
@@ -333,21 +259,21 @@ Validates tickets using the SAML 1.1 protocol.
```
-| Property | Description | Required
-|----------|-------|-----------
-| `casServerUrlPrefix ` | The start of the CAS server URL, i.e. `https://localhost:8443/cas` | Yes
-| `serverName` | The name of the server this application is hosted on. Service URL will be dynamically constructed using this, i.e. `https://localhost:8443` (you must include the protocol, but port is optional if it's a standard port). | Yes
-| `renew` | Specifies whether `renew=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all). Note that `renew` cannot be specified as local `init-param` setting. | No
-| `redirectAfterValidation ` | Whether to redirect to the same URL after ticket validation, but without the ticket in the parameter. Defaults to `true`. | No
-| `useSession ` | Whether to store the Assertion in session or not. If sessions are not used, tickets will be required for each request. Defaults to `true`. | No
-| `exceptionOnValidationFailure ` | whether to throw an exception or not on ticket validation failure. Defaults to `true` | No
-| `tolerance ` | The tolerance for drifting clocks when validating SAML tickets. Note that 10 seconds should be more than enough for most environments that have NTP time synchronization. Defaults to `1000 msec` | No
-| `sslConfigFile` | A reference to a properties file that includes SSL settings for client-side SSL config, used during back-channel calls. The configuration includes keys for `protocol` which defaults to `SSL`, `keyStoreType`, `keyStorePath`, `keyStorePass`, `keyManagerType` which defaults to `SunX509` and `certificatePassword`. | No.
-| `encoding` | Specifies the encoding charset the client should use | No
-| `hostnameVerifier` | Hostname verifier class name, used when making back-channel calls | No
-
-
-#### org.jasig.cas.client.validation.Cas20ProxyReceivingTicketValidationFilter
+| Property | Description | Required |
+|---------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------|
+| `casServerUrlPrefix ` | The start of the CAS server URL, i.e. `https://localhost:8443/cas` | Yes |
+| `serverName` | The name of the server this application is hosted on. Service URL will be dynamically constructed using this, i.e. `https://localhost:8443` (you must include the protocol, but port is optional if it's a standard port). | Yes |
+| `renew` | Specifies whether `renew=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all). Note that `renew` cannot be specified as local `init-param` setting. | No |
+| `redirectAfterValidation ` | Whether to redirect to the same URL after ticket validation, but without the ticket in the parameter. Defaults to `true`. | No |
+| `useSession ` | Whether to store the Assertion in session or not. If sessions are not used, tickets will be required for each request. Defaults to `true`. | No |
+| `exceptionOnValidationFailure ` | whether to throw an exception or not on ticket validation failure. Defaults to `true` | No |
+| `tolerance ` | The tolerance for drifting clocks when validating SAML tickets. Note that 10 seconds should be more than enough for most environments that have NTP time synchronization. Defaults to `1000 msec` | No |
+| `sslConfigFile` | A reference to a properties file that includes SSL settings for client-side SSL config, used during back-channel calls. The configuration includes keys for `protocol` which defaults to `SSL`, `keyStoreType`, `keyStorePath`, `keyStorePass`, `keyManagerType` which defaults to `SunX509` and `certificatePassword`. | No. |
+| `encoding` | Specifies the encoding charset the client should use | No |
+| `hostnameVerifier` | Hostname verifier class name, used when making back-channel calls | No |
+
+
+#### org.apereo.cas.client.validation.Cas20ProxyReceivingTicketValidationFilter
Validates the tickets using the CAS 2.0 protocol. If you provide either the `acceptAnyProxy` or the `allowedProxyChains` parameters, a `Cas20ProxyTicketValidator` will be constructed. Otherwise a general `Cas20ServiceTicketValidator` will be constructed that does not accept proxy tickets.
**Note**: If you are using proxy validation, you should place the `filter-mapping` of the validation filter before the authentication filter.
@@ -355,7 +281,7 @@ Validates the tickets using the CAS 2.0 protocol. If you provide either the `acc
```xml
CAS Validation Filter
- org.jasig.cas.client.validation.Cas20ProxyReceivingTicketValidationFilter
+ org.apereo.cas.client.validation.Cas20ProxyReceivingTicketValidationFiltercasServerUrlPrefixhttps://battags.ad.ess.rutgers.edu:8443/cas
@@ -371,42 +297,85 @@ Validates the tickets using the CAS 2.0 protocol. If you provide either the `acc
```
-| Property | Description | Required
-|----------|-------|-----------
-| `casServerUrlPrefix ` | The start of the CAS server URL, i.e. `https://localhost:8443/cas` | Yes
-| `serverName` | The name of the server this application is hosted on. Service URL will be dynamically constructed using this, i.e. `https://localhost:8443` (you must include the protocol, but port is optional if it's a standard port). | Yes
-| `renew` | Specifies whether `renew=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all). Note that `renew` cannot be specified as local `init-param` setting. | No
-| `redirectAfterValidation ` | Whether to redirect to the same URL after ticket validation, but without the ticket in the parameter. Defaults to `true`. | No
-| `useSession ` | Whether to store the Assertion in session or not. If sessions are not used, tickets will be required for each request. Defaults to `true`. | No
-| `exceptionOnValidationFailure ` | whether to throw an exception or not on ticket validation failure. Defaults to `true` | No
-| `proxyReceptorUrl ` | The URL to watch for `PGTIOU/PGT` responses from the CAS server. Should be defined from the root of the context. For example, if your application is deployed in `/cas-client-app` and you want the proxy receptor URL to be `/cas-client-app/my/receptor` you need to configure proxyReceptorUrl to be `/my/receptor`. | No
-| `acceptAnyProxy ` | Specifies whether any proxy is OK. Defaults to `false`. | No
-| `allowedProxyChains ` | Specifies the proxy chain. Each acceptable proxy chain should include a space-separated list of URLs (for exact match) or regular expressions of URLs (starting by the `^` character). Each acceptable proxy chain should appear on its own line. | No
-| `proxyCallbackUrl` | The callback URL to provide the CAS server to accept Proxy Granting Tickets. | No
-| `proxyGrantingTicketStorageClass ` | Specify an implementation of the ProxyGrantingTicketStorage class that has a no-arg constructor. | No
-| `sslConfigFile` | A reference to a properties file that includes SSL settings for client-side SSL config, used during back-channel calls. The configuration includes keys for `protocol` which defaults to `SSL`, `keyStoreType`, `keyStorePath`, `keyStorePass`, `keyManagerType` which defaults to `SunX509` and `certificatePassword`. | No.
-| `encoding` | Specifies the encoding charset the client should use | No
-| `secretKey` | The secret key used by the `proxyGrantingTicketStorageClass` if it supports encryption. | No
-| `cipherAlgorithm` | The algorithm used by the `proxyGrantingTicketStorageClass` if it supports encryption. Defaults to `DESede` | No
-| `millisBetweenCleanUps` | Startup delay for the cleanup task to remove expired tickets from the storage. Defaults to `60000 msec` | No
-| `ticketValidatorClass` | Ticket validator class to use/create | No
-| `hostnameVerifier` | Hostname verifier class name, used when making back-channel calls | No
-| `privateKeyPath` | The path to a private key to decrypt PGTs directly sent encrypted as an attribute | No
-| `privateKeyAlgorithm` | The algorithm of the private key. Defaults to `RSA` | No
-
-#### org.jasig.cas.client.validation.Cas30ProxyReceivingTicketValidationFilter
+| Property | Description | Required |
+|------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------|
+| `casServerUrlPrefix ` | The start of the CAS server URL, i.e. `https://localhost:8443/cas` | Yes |
+| `serverName` | The name of the server this application is hosted on. Service URL will be dynamically constructed using this, i.e. `https://localhost:8443` (you must include the protocol, but port is optional if it's a standard port). | Yes |
+| `renew` | Specifies whether `renew=true` should be sent to the CAS server. Valid values are either `true/false` (or no value at all). Note that `renew` cannot be specified as local `init-param` setting. | No |
+| `redirectAfterValidation ` | Whether to redirect to the same URL after ticket validation, but without the ticket in the parameter. Defaults to `true`. | No |
+| `useSession ` | Whether to store the Assertion in session or not. If sessions are not used, tickets will be required for each request. Defaults to `true`. | No |
+| `exceptionOnValidationFailure ` | whether to throw an exception or not on ticket validation failure. Defaults to `true` | No |
+| `proxyReceptorUrl ` | The URL to watch for `PGTIOU/PGT` responses from the CAS server. Should be defined from the root of the context. For example, if your application is deployed in `/cas-client-app` and you want the proxy receptor URL to be `/cas-client-app/my/receptor` you need to configure proxyReceptorUrl to be `/my/receptor`. | No |
+| `acceptAnyProxy ` | Specifies whether any proxy is OK. Defaults to `false`. | No |
+| `allowedProxyChains ` | Specifies the proxy chain. Each acceptable proxy chain should include a space-separated list of URLs (for exact match) or regular expressions of URLs (starting by the `^` character). Each acceptable proxy chain should appear on its own line. | No |
+| `proxyCallbackUrl` | The callback URL to provide the CAS server to accept Proxy Granting Tickets. | No |
+| `proxyGrantingTicketStorageClass ` | Specify an implementation of the ProxyGrantingTicketStorage class that has a no-arg constructor. | No |
+| `sslConfigFile` | A reference to a properties file that includes SSL settings for client-side SSL config, used during back-channel calls. The configuration includes keys for `protocol` which defaults to `SSL`, `keyStoreType`, `keyStorePath`, `keyStorePass`, `keyManagerType` which defaults to `SunX509` and `certificatePassword`. | No. |
+| `encoding` | Specifies the encoding charset the client should use | No |
+| `secretKey` | The secret key used by the `proxyGrantingTicketStorageClass` if it supports encryption. | No |
+| `cipherAlgorithm` | The algorithm used by the `proxyGrantingTicketStorageClass` if it supports encryption. Defaults to `DESede` | No |
+| `millisBetweenCleanUps` | Startup delay for the cleanup task to remove expired tickets from the storage. Defaults to `60000 msec` | No |
+| `ticketValidatorClass` | Ticket validator class to use/create | No |
+| `hostnameVerifier` | Hostname verifier class name, used when making back-channel calls | No |
+| `privateKeyPath` | The path to a private key to decrypt PGTs directly sent encrypted as an attribute | No |
+| `privateKeyAlgorithm` | The algorithm of the private key. Defaults to `RSA` | No |
+
+#### org.apereo.cas.client.validation.Cas30ProxyReceivingTicketValidationFilter
Validates the tickets using the CAS 3.0 protocol. If you provide either the `acceptAnyProxy` or the `allowedProxyChains` parameters,
a `Cas30ProxyTicketValidator` will be constructed. Otherwise a general `Cas30ServiceTicketValidator` will be constructed that does not
accept proxy tickets. Supports all configurations that are available for `Cas20ProxyReceivingTicketValidationFilter`.
-#### org.jasig.cas.client.validation.json.Cas30JsonProxyReceivingTicketValidationFilter
-Indentical to `Cas30ProxyReceivingTicketValidationFilter`, yet the filter is able to accept validation responses from CAS
+#### org.apereo.cas.client.validation.Cas30JsonProxyReceivingTicketValidationFilter
+Identical to `Cas30ProxyReceivingTicketValidationFilter`, yet the filter is able to accept validation responses from CAS
that are formatted as JSON per guidelines laid out by the CAS protocol.
See the [protocol documentation](https://apereo.github.io/cas/5.1.x/protocol/CAS-Protocol-Specification.html)
for more info.
+
+#### org.apereo.cas.client.validation.CasJWTTicketValidationFilter
+Validates service tickets that issued by the CAS server as JWTs.
+
+Supported JWTs are:
+
+- The JWT must be signed and encrypted, in that order, or...
+- The JWT must be encrypted and signed, in that order, or...
+- The JWT must be encrypted.
+
+```xml
+
+ CAS Validation Filter
+ org.apereo.cas.client.validation.CasJWTTicketValidationFilter
+
+ signingKey
+ ...
+
+
+ encryptionKey
+ ...
+
+
+
+ CAS Validation Filter
+ /*
+
+```
+
+| Property | Description | Required |
+|---------------------------|------------------------------------------------------------------------------------------|----------|
+| `signingKey ` | The signing key. Only `AES` secret keys are supported. | Yes |
+| `encryptionKey ` | The encryption key. Only `AES` secret keys are supported. | Yes |
+| `expectedIssuer ` | `iss` claim value that is required to match what is in the JWT. | Yes |
+| `expectedAudience ` | `aud` claim value that is required to match what is in the JWT. | Yes |
+| `encryptionKeyAlgorithm ` | Default is `AES`. | No |
+| `encryptionKeyAlgorithm ` | Default is `AES`. | No |
+| `requiredClaims ` | Default is `sub,aud,iat,jti,exp,iss`. | No |
+| `base64EncryptionKey ` | If encryption key should be base64-decoded first. Default is `true`. | No |
+| `base64SigningKey ` | If encryption key should be base64-decoded first. Default is `false`. | No |
+| `maxClockSkew ` | Maximum acceptable clock skew when validating expiration dates. Default is `60` seconds. | No |
+
##### Proxy Authentication vs. Distributed Caching
-The client has support for clustering and distributing the TGT state among application nodes that are behind a load balancer. In order to do so, the parameter needs to be defined as such for the filter.
+The client has support for clustering and distributing the TGT state among application nodes that are behind a load balancer. In order to do so,
+the parameter needs to be defined as such for the filter.
###### Ehcache
@@ -415,14 +384,14 @@ Configure the client:
```xml
proxyGrantingTicketStorageClass
- org.jasig.cas.client.proxy.EhcacheBackedProxyGrantingTicketStorageImpl
+ org.apereo.cas.client.EhcacheBackedProxyGrantingTicketStorageImpl
```
The setting provides an implementation for proxy storage using EhCache to take advantage of its replication features so that the PGT is successfully replicated and shared among nodes, regardless which node is selected as the result of the load balancer rerouting.
Configuration of this parameter is not enough. The EhCache configuration needs to enable the replication mechanism through once of its suggested ways. A sample of that configuration based on RMI replication can be found here. Please note that while the sample is done for a distributed ticket registry implementation, the basic idea and configuration should easily be transferable.
-When loading from the `web.xml`, the Jasig CAS Client relies on a series of default values, one of which being that the cache must be configured in the default location (i.e. `classpath:ehcache.xml`).
+When loading from the `web.xml`, the Apereo CAS Client relies on a series of default values, one of which being that the cache must be configured in the default location (i.e. `classpath:ehcache.xml`).
```xml
proxyGrantingTicketStorageClass
- org.jasig.cas.client.proxy. MemcachedBackedProxyGrantingTicketStorageImpl
+ org.apereo.cas.client.proxy.MemcachedBackedProxyGrantingTicketStorageImpl
```
When loading from the `web.xml`, the Client relies on a series of default values, one of which being that the list of memcached servers must be defined in `/cas/casclient_memcached_hosts.txt` on the classpath). The file is a simple list of `:` on separate lines. **BE SURE NOT TO HAVE EXTRA LINE BREAKS**.
-
-#### org.jasig.cas.client.util.HttpServletRequestWrapperFilter
+
+#### org.apereo.cas.client.HttpServletRequestWrapperFilter
+
Wraps an `HttpServletRequest` so that the `getRemoteUser` and `getPrincipal` return the CAS related entries.
```xml
CAS HttpServletRequest Wrapper Filter
- org.jasig.cas.client.util.HttpServletRequestWrapperFilter
+ org.apereo.cas.client.HttpServletRequestWrapperFilterCAS HttpServletRequest Wrapper Filter
@@ -471,19 +442,20 @@ Wraps an `HttpServletRequest` so that the `getRemoteUser` and `getPrincipal` ret
```
-| Property | Description | Required
-|----------|-------|-----------
-| `roleAttribute` | Used to determine the principal role. | No
-| `ignoreCase` | Whether role checking should ignore case. Defaults to `false` | No
+| Property | Description | Required |
+|-----------------|---------------------------------------------------------------|----------|
+| `roleAttribute` | Used to determine the principal role. | No |
+| `ignoreCase` | Whether role checking should ignore case. Defaults to `false` | No |
-
-#### org.jasig.cas.client.util.AssertionThreadLocalFilter
+
+
+#### org.apereo.cas.client.AssertionThreadLocalFilter
Places the `Assertion` in a `ThreadLocal` for portions of the application that need access to it. This is useful when the Web application that this filter "fronts" needs to get the Principal name, but it has no access to the `HttpServletRequest`, hence making `getRemoteUser()` call impossible.
```xml
CAS Assertion Thread Local Filter
- org.jasig.cas.client.util.AssertionThreadLocalFilter
+ org.apereo.cas.client.AssertionThreadLocalFilterCAS Assertion Thread Local Filter
@@ -491,20 +463,20 @@ Places the `Assertion` in a `ThreadLocal` for portions of the application that n
```
-
-#### org.jasig.cas.client.util.ErrorRedirectFilter
-Filters that redirects to the supplied url based on an exception. Exceptions and the urls are configured via init filter name/param values.
+
-| Property | Description | Required
-|----------|-------|-----------
-| `defaultErrorRedirectPage` | Default url to redirect to, in case no error matches are found. | Yes
-| `java.lang.Exception` | Fully qualified exception name. Its value must be redirection url | No
+#### org.apereo.cas.client.ErrorRedirectFilter
+Filters that redirects to the supplied url based on an exception. Exceptions and the urls are configured via init filter name/param values.
+| Property | Description | Required |
+|----------------------------|-------------------------------------------------------------------|----------|
+| `defaultErrorRedirectPage` | Default url to redirect to, in case no error matches are found. | Yes |
+| `java.lang.Exception` | Fully qualified exception name. Its value must be redirection url | No |
```xml
CAS Error Redirect Filter
- org.jasig.cas.client.util.ErrorRedirectFilter
+ org.apereo.cas.client.ErrorRedirectFilterjava.lang.Exception/error.jsp
@@ -522,6 +494,7 @@ Filters that redirects to the supplied url based on an exception. Exceptions an
+
### Client Configuration Using Spring
Configuration via Spring IoC will depend heavily on `DelegatingFilterProxy` class. For each filter that will be configured for CAS via Spring, a corresponding `DelegatingFilterProxy` is needed in the web.xml.
@@ -550,7 +523,7 @@ As the `HttpServletRequestWrapperFilter` and `AssertionThreadLocalFilter` have n
```xml
-
+
@@ -575,10 +548,10 @@ As the `HttpServletRequestWrapperFilter` and `AssertionThreadLocalFilter` have n
```xml
-
+
@@ -590,10 +563,10 @@ Configuration to validate tickets:
```xml
-
+
@@ -604,12 +577,12 @@ Configuration to accept a Proxy Granting Ticket:
```xml
@@ -622,11 +595,11 @@ Configuration to accept any Proxy Ticket (and Proxy Granting Tickets):
```xml
-
@@ -640,11 +613,11 @@ Configuration to accept Proxy Ticket from a chain (and Proxy Granting Tickets):
```xml
-
@@ -670,7 +643,7 @@ The specific filters can be configured in the following ways. Please see the Jav
```xml
- org.jasig.cas.client
+ org.apereo.cas.clientcas-client-support-springboot${java.cas.client.version}
@@ -681,7 +654,7 @@ The specific filters can be configured in the following ways. Please see the Jav
```groovy
dependencies {
...
- compile 'org.jasig.cas.client:cas-client-support-springboot:${java.cas.client.version}'
+ implementation 'org.apereo.cas.client:cas-client-support-springboot:${java.cas.client.version}'
...
}
```
@@ -798,36 +771,6 @@ class CasProtectedApplication implements CasClientConfigurer {
authenticationFilter.getInitParameters().put("serviceParameterName", "targetService");
}
}
-```
-
-
-
-### Client Configuration Using JNDI
-
-Configuring the CAS client via JNDI is essentially the same as configuring the client via the `web.xml`, except the properties will reside in JNDI and not in the `web.xml`.
-All properties that are placed in JNDI should be placed under `java:comp/env/cas`
-
-We use the following conventions:
-1. JNDI will first look in `java:comp/env/cas/{SHORT FILTER NAME}/{PROPERTY NAME}` (i.e. `java:comp/env/cas/AuthenticationFilter/serverName`)
-2. JNDI will as a last resort look in `java:comp/env/cas/{PROPERTY NAME}` (i.e. `java:comp/env/cas/serverName`)
-
-
-#### Example
-This is an update to the `META-INF/context.xml` that is included in Tomcat's Manager application:
-
-```xml
-
-
-
-
-
-
-
-
-
```
@@ -838,14 +781,14 @@ The `SingleSignOutFilter` can affect character encoding. This becomes most obvio
#### Configuration
-| Property | Description | Required
-|----------|-------|-----------
-| `artifactParameterName` | The ticket artifact parameter name. Defaults to `ticket`| No
-| `logoutParameterName` | Defaults to `logoutRequest` | No
-| `relayStateParameterName` | Defaults to `RelayState` | No
-| `eagerlyCreateSessions` | Defaults to `true` | No
-| `artifactParameterOverPost` | Defaults to `false` | No
-| `logoutCallbackPath` | The path which is expected to receive logout callback requests from the CAS server. This is necessary if your app needs access to the raw input stream when handling form posts. If not configured, the default behavior will check every form post for a logout parameter. | No
+| Property | Description | Required |
+|-----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------|
+| `artifactParameterName` | The ticket artifact parameter name. Defaults to `ticket` | No |
+| `logoutParameterName` | Defaults to `logoutRequest` | No |
+| `relayStateParameterName` | Defaults to `RelayState` | No |
+| `eagerlyCreateSessions` | Defaults to `true` | No |
+| `artifactParameterOverPost` | Defaults to `false` | No |
+| `logoutCallbackPath` | The path which is expected to receive logout callback requests from the CAS server. This is necessary if your app needs access to the raw input stream when handling form posts. If not configured, the default behavior will check every form post for a logout parameter. | No |
#### CAS Protocol
@@ -853,7 +796,7 @@ The `SingleSignOutFilter` can affect character encoding. This becomes most obvio
```xml
CAS Single Sign Out Filter
- org.jasig.cas.client.session.SingleSignOutFilter
+ org.apereo.cas.client.session.SingleSignOutFilter
...
@@ -862,7 +805,7 @@ The `SingleSignOutFilter` can affect character encoding. This becomes most obvio
...
- org.jasig.cas.client.session.SingleSignOutHttpSessionListener
+ org.apereo.cas.client.session.SingleSignOutHttpSessionListener
```
@@ -872,7 +815,7 @@ The `SingleSignOutFilter` can affect character encoding. This becomes most obvio
```xml
CAS Single Sign Out Filter
- org.jasig.cas.client.session.SingleSignOutFilter
+ org.apereo.cas.client.session.SingleSignOutFilterartifactParameterNameSAMLart
@@ -885,7 +828,7 @@ The `SingleSignOutFilter` can affect character encoding. This becomes most obvio
...
- org.jasig.cas.client.session.SingleSignOutHttpSessionListener
+ org.apereo.cas.client.session.SingleSignOutHttpSessionListener
```
@@ -912,8 +855,8 @@ It is expected that for JEE applications both authentication and authorization s
```
cas {
- org.jasig.cas.client.jaas.CasLoginModule required
- ticketValidatorClass="org.jasig.cas.client.validation.Saml11TicketValidator"
+ jaas.org.apereo.cas.client.CasLoginModule required
+ ticketValidatorClass="org.apereo.cas.client.validation.Saml11TicketValidator"
casServerUrlPrefix="https://cas.example.com/cas"
tolerance="20000"
service="https://webapp.example.com/webapp"
@@ -927,618 +870,24 @@ cas {
```
-| Property | Description | Required
-|----------|-------|-----------|
-| `ticketValidatorClass ` | Fully-qualified class name of CAS ticket validator class. | Yes
-| `casServerUrlPrefix` | URL to root of CAS Web application context. | Yes
-| `service` | CAS service parameter that may be overridden by callback handler. **Note**: service must be specified by at least one component such that it is available at service ticket validation time. | No
-| `defaultRoles` | Comma-delimited list of static roles applied to all authenticated principals. | No
-| `roleAttributeNames` | Comma-delimited list of attribute names that describe role data delivered to CAS in the service-ticket validation response that should be applied to the current authenticated principal. | No
-| `principalGroupName` | The name of a group principal containing the primary principal name of the current JAAS subject. The default value is `CallerPrincipal`. | No
-| `roleGroupName` | The name of a group principal containing all role data. The default value is `Roles`. | No
-| `cacheAssertions` | Flag to enable assertion caching. This may be required for JAAS providers that attempt to periodically reauthenticate to renew principal. Since CAS tickets are one-time-use, a cached assertion must be provided on reauthentication. | No
-| `cacheTimeout` | Assertion cache timeout in minutes. | No
-| `tolerance` | The tolerance for drifting clocks when validating SAML tickets. | No
+| Property | Description | Required |
+|-------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------|
+| `ticketValidatorClass ` | Fully-qualified class name of CAS ticket validator class. | Yes |
+| `casServerUrlPrefix` | URL to root of CAS Web application context. | Yes |
+| `service` | CAS service parameter that may be overridden by callback handler. **Note**: service must be specified by at least one component such that it is available at service ticket validation time. | No |
+| `defaultRoles` | Comma-delimited list of static roles applied to all authenticated principals. | No |
+| `roleAttributeNames` | Comma-delimited list of attribute names that describe role data delivered to CAS in the service-ticket validation response that should be applied to the current authenticated principal. | No |
+| `principalGroupName` | The name of a group principal containing the primary principal name of the current JAAS subject. The default value is `CallerPrincipal`. | No |
+| `roleGroupName` | The name of a group principal containing all role data. The default value is `Roles`. | No |
+| `cacheAssertions` | Flag to enable assertion caching. This may be required for JAAS providers that attempt to periodically reauthenticate to renew principal. Since CAS tickets are one-time-use, a cached assertion must be provided on reauthentication. | No |
+| `cacheTimeout` | Assertion cache timeout in minutes. | No |
+| `tolerance` | The tolerance for drifting clocks when validating SAML tickets. | No |
### Programmatic JAAS login using the Servlet 3
-A `org.jasig.cas.client.jaas.Servlet3AuthenticationFilter` servlet filter that performs a programmatic JAAS login using the Servlet 3.0 `HttpServletRequest#login()` facility. This component should be compatible with any servlet container that supports the Servlet 3.0/JEE6 specification.
+A `jaas.org.apereo.cas.client.Servlet3AuthenticationFilter` servlet filter that performs a programmatic JAAS login using the Servlet 3.0 `HttpServletRequest#login()` facility. This component should be compatible with any servlet container that supports the Servlet 3.0/JEE6 specification.
The filter executes when it receives a CAS ticket and expects the
`CasLoginModule` JAAS module to perform the CAS ticket validation in order to produce an `AssertionPrincipal` from which the CAS assertion is obtained and inserted into the session to enable SSO.
If a `service` init-param is specified for this filter, it supersedes
the service defined for the `CasLoginModule`.
-
-
-## JBoss Integration
-
-In keeping with CAS integration for Java applications, a JEE container-specific servlet filter is needed to protect JEE Web applications. The JBoss `WebAuthenticationFilter` component provided a convenient integration piece between a servlet filter and the JAAS framework, so a complete integration solution is available only for JBoss AS versions that provide the `WebAuthenticationFilter` class. The JAAS support should be extensible to any JEE container with additional development.
-
-For JBoss it is vitally important to use the correct values for `principalGroupName` and `roleGroupName`. Additionally, the `cacheAssertions` and `cacheTimeout` are required since JBoss by default attempts to reauthenticate the JAAS principal with a fairly aggressive default timeout. Since CAS tickets are single-use authentication tokens by default, assertion caching is required to support periodic reauthentication.
-
-
-### Configure Servlet Filters
-
-Integration with the servlet pipeline is required for a number of purposes:
-
-1. Examine servlet request for an authenticated session
-2. Redirect to CAS server for unauthenticated sessions
-3. Provide service URL and CAS ticket to JAAS pipeline for validation
-
-The `WebAuthenticationFilter` performs these operations for the JBoss AS container. It is important to note that this filter simply collects the service URL and CAS ticket from the request and passes it to the JAAS pipeline. It is assumed that the `CasLoginModule` will be present in the JAAS pipeline to consume the data and perform ticket validation. The following web.xml excerpts demonstrate how to integrate WebAuthenticationFilter into a JEE Web application.
-
-
-```xml
-...
-
- CASWebAuthenticationFilter
- org.jasig.cas.client.jboss.authentication.WebAuthenticationFilter
-
-
-
- CASAuthenticationFilter
- org.jasig.cas.client.authentication.AuthenticationFilter
-
- casServerLoginUrl
- https://cas.example.com/cas/login
-
-
-...
-
-...
-```
-
-The JAAS LoginModule configuration in `conf/login-config.xml` may require the following changes in a JBoss environment:
-
-```xml
-
-
-
- org.jasig.cas.client.validation.Saml11TicketValidator
- http://yourcasserver/cas
- 20000
- admin,user
- memberOf,eduPersonAffiliation,authorities
- CallerPrincipal
- Roles
- true
- 480
-
-
-
-```
-It may be necessary to modify the JBoss `server.xml` and uncomment:
-
-```xml
-
-```
-
-Remember not to add `` and `` elements in your `web.xml`.
-
-If you have any trouble, you can enable the log of cas in `jboss-logging.xml` by adding:
-
-```xml
-
-
-
-```
-
-
-## Tomcat 6/7/8/9 Integration
-The client supports container-based CAS authentication and authorization support for the Tomcat servlet container.
-
-Suppose a single Tomcat container hosts multiple Web applications with similar authentication and authorization needs. Prior to Tomcat container support, each application would require a similar configuration of CAS servlet filters and authorization configuration in the `web.xml` servlet descriptor. Using the new container-based authentication/authorization feature, a single CAS configuration can be applied to the container and leveraged by all Web applications hosted by the container.
-
-CAS authentication support for Tomcat is based on the Tomcat-specific Realm component. The Realm component has a fairly broad surface area and RealmBase is provided as a convenient superclass for custom implementations; the CAS realm implementations derive from `RealmBase`. Unfortunately RealmBase and related components have proven to change over both major and minor number releases, which requires version-specific CAS components for integration. We have provided 3 packages with similar components with the hope of supporting all 6.x, 7.x and 8.x versions. **No support for 5.x is provided.**
-
-
-### Component Overview
-In the following discussion of components, only the Tomcat 8.x components are mentioned. Tomcat 8.0.x components are housed inside
-`org.jasig.cas.client.tomcat.v8` while Tomcat 8.5.x components are inside `org.jasig.cas.client.tomcat.v85`. Tomcat 9 packages are
-available at `org.jasig.cas.client.tomcat.v90`. You should be able to use the same exact configuration between the two modules provided package names are adjusted for each release.
-
-The Tomcat 7.0.x and 6.0.x components have exactly the same name, but **are in the tomcat.v7 and tomcat.v6 packages**, e.g.
-`org.jasig.cas.client.tomcat.v7.Cas20CasAuthenticator` or `org.jasig.cas.client.tomcat.v6.Cas20CasAuthenticator`.
-
-
-#### Authenticators
-Authenticators are responsible for performing CAS authentication using a particular protocol. All protocols supported by the Jasig Java CAS client are supported: CAS 1.0, CAS 2.0, and SAML 1.1. The following components provide protocol-specific support:
-
-```
-org.jasig.cas.client.tomcat.v8.Cas10CasAuthenticator
-org.jasig.cas.client.tomcat.v8.Cas20CasAuthenticator
-org.jasig.cas.client.tomcat.v8.Cas20ProxyCasAuthenticator
-org.jasig.cas.client.tomcat.v8.Saml11Authenticator
-```
-
-
-#### Realms
-In terms of CAS configuration, Tomcat realms serve as containers for users and role definitions. The roles defined in a Tomcat realm may be referenced in the web.xml servlet descriptor to define authorization constraints on Web applications hosted by the container. Two sources of user/role data are supported:
-
-```
-org.jasig.cas.client.tomcat.v8.PropertiesCasRealm
-org.jasig.cas.client.tomcat.v8.AssertionCasRealm
-```
-
-`PropertiesCasRealm` uses a Java properties file as a source of static user/role information. This component is conceptually similar to the `MemoryRealm` component that ships with Tomcat and defines user/role data via XML configuration. The PropertiesCasRealm is different in that it explicitly lacks support for passwords, which have no use with CAS.
-
-`AssertionCasRealm` is designed to be used in conjunction with the SAML 1.1. protocol to take advantage of CAS attribute release to provide for dynamic user/role data driven by the CAS server. With this component the deployer may define a role attribute, e.g. memberOf, which could be backed by LDAP group membership information. In that case the user would be added to all roles defined in the SAML attribute assertion for values of the the `memberOf` attribute.
-
-
-#### Valves
-A number of Tomcat valves are provided to handle functionality outside Realms and Authenticators.
-
-##### Logout Valves
-Logout valves provide a way of destroying the CAS authentication state bound to the container for a particular user/session; the destruction of authenticated state is synonymous with logout for the container and its hosted applications. (Note this does not destroy the CAS SSO session.) The implementations provide various strategies to map a URI onto the state-destroying logout function.
-
-```
-org.jasig.cas.client.tomcat.v8.StaticUriLogoutValve
-org.jasig.cas.client.tomcat.v8.RegexUriLogoutValve
-```
-
-##### SingleSignOutValve
-The `org.jasig.cas.client.tomcat.v8.SingleSignOutValve` allows the container to participate in CAS single sign-out. In particular this valve handles the SAML LogoutRequest message sent from the CAS server that is delivered when the CAS SSO session ends.
-
-##### ProxyCallbackValve
-The `org.jasig.cas.client.tomcat.v8.ProxyCallbackValve` provides a handler for watching request URIs for requests that contain a proxy callback request in support of the CAS 2.0 protocol proxy feature.
-
-
-### Container Setup
-The version-specific CAS libraries must be placed on the container classpath, `$CATALINA_HOME/lib`.
-
-
-### Context Configuration
-The Realm, Authenticator, and Valve components are wired together inside a Tomcat Context configuration element. The location and scope of the Context determines the scope of the applied configuration. To apply a CAS configuration to every Web application hosted in the container, configure the default Context at `$CATALINA_HOME/conf/context.xml`. Note that individual Web applications/servlets can override the default context; see the Context Container reference for more information.
-
-Alternatively, CAS configuration can be applied to individual Web applications through a Context configuration element located in a `$CONTEXT_NAME.xml` file placed in `$CATALINA_HOME/conf/$ENGINE/$HOST`, where `$ENGINE` is typically Catalina and `$HOST` is `localhost`, `$CATALINA_HOME/conf/Catalina/localhost`. For example, to configure the Tomcat manager servlet, a `manager.xml` file contains Context configuration elements.
-
-```xml
-
-
-
-
-
-
-
-
-
-
-
-
-```
-
-The following example shows how to configure a Context for dynamic role data provided by the CAS attribute release feature.
-
-```xml
-
-
-
-
-
-
-
-
-
-```
-
-
-## Jetty Integration
-Since version 3.4.2, the Java CAS Client supports Jetty container integration via the following module:
-
-```xml
-
- org.jasig.cas.client
- cas-client-integration-jetty
- ${cas-client.version}
-
-```
-
-Both programmatic (embedded) and context configuration are supported.
-
-### Jetty Embedded Configuration
-```
-# CAS configuration parameters
-String hostName = "app.example.com";
-String casServerBaseUrl = "cas.example.com/cas";
-String casRoleAttribute = "memberOf";
-boolean casRenew = false;
-int casTolerance = 5000;
-
-# Jetty wiring
-WebAppContext context = new WebAppContext("/path/to/context", "contextPath");
-context.setTempDirectory("/tmp/jetty/work"));
-context.setInitParameter("org.eclipse.jetty.servlet.Default.dirAllowed", "false");
-SessionCookieConfig config = context.getSessionHandler().getSessionManager().getSessionCookieConfig();
-config.setHttpOnly(true);
-config.setSecure(true);
-Saml11TicketValidator validator = new Saml11TicketValidator(casServerBaseUrl);
-validator.setRenew(casRenew);
-validator.setTolerance(casTolerance);
-CasAuthenticator authenticator = new CasAuthenticator();
-authenticator.setRoleAttribute(casRoleAttribute);
-authenticator.setServerNames(hostName);
-authenticator.setTicketValidator(validator);
-context.getSecurityHandler().setAuthenticator(authenticator);
-```
-
-### Jetty Context Configuration
-```xml
-
-
-
-
- /
- /webapps/yourapp
-
-
-
- app.example.com
-
-
- https://cas.example.com/cas
-
-
-
-
-
-
-
-```
-
-
-## Atlassian Integration
-The clien includes Atlassian Confluence and JIRA support. Support is enabled by a custom CAS authenticator that extends the default authenticators.
-
-
-### Configuration
-
-
-#### $JIRA_HOME Location
-
-- WAR/EAR Installation: /webapp
-`/opt/atlassian/jira/atlassian-jira-enterprise-x.y.z/webapp`
-
-- Standalone: /atlassian-jira
-`/opt/atlassian/jira/atlassian-jira-enterprise-x.y.z-standalone/atlassian-jira`
-
-
-#### $CONFLUENCE_INSTALL Description
-
-- /confluence
-`/opt/atlassian/confluence/confluence-x.y.z/confluence`
-
-
-#### Changes to web.xml
-Add the CAS filters to the end of the filter list. See `web.xml` configuration of the client.
-
-
-
-#### Modify the seraph-config.xml
-To rely on the Single Sign Out functionality to sign off of Jira, comment out the normal logout URL and replace it with the CAS logout URL. Also, change the login links to point to the CAS login service.
-
-```xml
-
-
- login.url
-
- http://cas.institution.edu/cas/login?service=${originalurl}
-
-
-
- link.login.url
-
-
- http://cas.institution.edu/cas/login?service=${originalurl}
-
-
-
- logout.url
-
- https://cas.institution.edu/cas/logout
-
-```
-
-
-#### CAS Authenticator
-Comment out the `DefaultAuthenticator` like so in `[$JIRA_HOME|$CONFLUENCE_INSTALL]/WEB-INF/classes/seraph-config.xml`:
-
-```xml
-
-
-
-```
-
-For JIRA, add in the Client Jira Authenticator:
-
-```xml
-
-
-
-```
-
-For Confluence, add in the Client Confluence Authenticator:
-
-```xml
-
-
-
-```
-
-
-#### Confluence CAS Logout
-
-As of this writing, Atlassian doesn't support a config option yet (like Jira). To rely on the Single Sign Out functionality to sign off of Confluence we need to modify the logout link.
-
-
-- Copy `$CONFLUENCE_INSTALL/WEB-INF/lib/confluence-x.x.x.jar` to a temporary directory
-- `mkdir /tmp/confluence-jar && cp WEB-INF/lib/confluence-x.y.z.jar /tmp/confluence-jar`
-- Unpack the jar
-- `cd /tmp/confluence-jar && jar xvf confluence-x.y.z.jar`
-- `cp xwork.xml $CONFLUENCE_INSTALL/WEB-INF/classes`
-- `cp xwork.xml $CONFLUENCE_INSTALL/WEB-INF/classes/ && cd $CONFLUENCE_INSTALL/WEB-INF/classes/`
-- Edit `$CONFLUENCE_INSTALL/WEB-INF/classes/xwork.xml`, find the logout action and comment out the success result and replace it with this one:
-
-```xml
-
-
-https://cas.institution.edu/cas/logout
-
-```
-
-
-#### Copy Jars
-Copy cas-client-core-x.y.x.jar and cas-client-integration-atlassian-x.y.x.jar to `$JIRA_HOME/WEB-INF/lib`
-
-
-## Spring Security Integration
-This configuration tested against the sample application that is included with Spring Security. As of this writing, replacing the `applicationContext-security.xml` in the sample application with the one below would enable this alternative configuration. We can not guarantee this version will work without modification in future versions of Spring Security.
-
-
-### Changes to web.xml
-
-```xml
-...
-
- contextConfigLocation
-
- /WEB-INF/applicationContext-security.xml
-
-
-
-
- log4jConfigLocation
- /WEB-INF/classes/log4j.properties
-
-
-
- webAppRootKey
- cas.root
-
-
-
- CAS Single Sign Out Filter
- org.jasig.cas.client.session.SingleSignOutFilter
-
- casServerUrlPrefix
- https://cas.example.com/cas
-
-
-
-
- springSecurityFilterChain
- org.springframework.web.filter.DelegatingFilterProxy
-
-
-
- CAS Single Sign Out Filter
- /*
-
-
-
- springSecurityFilterChain
- /*
-
-
-
- org.jasig.cas.client.session.SingleSignOutHttpSessionListener
-
-
-
- org.springframework.web.context.ContextLoaderListener
-
-
-
- org.springframework.web.util.Log4jConfigListener
-
-
-
- 403
- /casfailed.jsp
-
-...
-```
-
-The important additions to the `web.xml` include the addition of the 403 error page. 403 is what the CAS Validation Filter will throw if it has a problem with the ticket. Also, if you want Single Log Out, you should enable the `SingleSignOutHttpSessionListener`.
-
-
-### Changes to applicationContext-security.xml
-
-```xml
-...
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-...
-```
-
-1. You should replace the `userService` with something that checks your user storage.
-2. Replace the `serverName` and `casServerLoginUrl` with your values (or better yet, externalize them).
-3. Replace the URLs with the URL configuration for your application.
diff --git a/cas-client-core/NOTICE b/cas-client-core/NOTICE
index 3e0a7e711..5e01c5329 100644
--- a/cas-client-core/NOTICE
+++ b/cas-client-core/NOTICE
@@ -27,7 +27,7 @@ This project includes:
Jackson-annotations under The Apache Software License, Version 2.0
Jackson-core under The Apache Software License, Version 2.0
jackson-databind under The Apache Software License, Version 2.0
- Jasig CAS Client for Java - Core under Apache License Version 2.0
+ Apereo CAS Client for Java - Core under Apache License Version 2.0
Java Servlet API under CDDL + GPLv2 with classpath exception
JavaBeans Activation Framework API jar under CDDL/GPLv2+CE
JAXB Core under CDDL+GPL License
diff --git a/cas-client-core/pom.xml b/cas-client-core/pom.xml
index cb7c2ca28..4fed89698 100644
--- a/cas-client-core/pom.xml
+++ b/cas-client-core/pom.xml
@@ -20,21 +20,21 @@
-->
- org.jasig.cas.client
- 3.6.4
+ org.apereo.cas.client
+ 4.1.2-SNAPSHOTcas-client4.0.0cas-client-corejar
- Jasig CAS Client for Java - Core
+ Apereo CAS Client for Java - Coreorg.apache.maven.pluginsmaven-jar-plugin
- 3.1.1
+ 3.5.1
@@ -50,16 +50,21 @@
xml-securityxmlsec
- 1.3.0
+ ${xmlsec.version}runtimetrue
+
+ com.nimbusds
+ nimbus-jose-jwt
+
+
com.fasterxml.jackson.corejackson-databind
-
+
org.springframeworkspring-beans
@@ -72,7 +77,7 @@
spring-webprovided
-
+
org.springframeworkspring-test
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/Protocol.java b/cas-client-core/src/main/java/org/apereo/cas/client/Protocol.java
similarity index 94%
rename from cas-client-core/src/main/java/org/jasig/cas/client/Protocol.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/Protocol.java
index c51929b0d..429a281b2 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/Protocol.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/Protocol.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,7 +16,7 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client;
+package org.apereo.cas.client;
/**
* Simple enumeration to hold/capture some of the standard request parameters used by the various protocols.
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/AttributePrincipal.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/AttributePrincipal.java
similarity index 94%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/AttributePrincipal.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/AttributePrincipal.java
index 23480fb90..3e4dcfdc6 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/AttributePrincipal.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/AttributePrincipal.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,7 +16,7 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
import java.io.Serializable;
import java.security.Principal;
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/AttributePrincipalImpl.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/AttributePrincipalImpl.java
similarity index 82%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/AttributePrincipalImpl.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/AttributePrincipalImpl.java
index f67c006e0..3e85f8bb9 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/AttributePrincipalImpl.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/AttributePrincipalImpl.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,15 +16,18 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
+
+import org.apereo.cas.client.proxy.ProxyRetriever;
+import org.apereo.cas.client.util.CommonUtils;
-import java.util.Collections;
-import java.util.Map;
-import org.jasig.cas.client.proxy.ProxyRetriever;
-import org.jasig.cas.client.util.CommonUtils;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
+import java.io.Serial;
+import java.util.Collections;
+import java.util.Map;
+
/**
* Concrete implementation of the AttributePrincipal interface.
*
@@ -36,6 +39,7 @@ public class AttributePrincipalImpl extends SimplePrincipal implements Attribute
private static final Logger LOGGER = LoggerFactory.getLogger(AttributePrincipalImpl.class);
/** Unique Id for Serialization */
+ @Serial
private static final long serialVersionUID = -1443182634624927187L;
/** Map of key/value pairs about this principal. */
@@ -53,7 +57,7 @@ public class AttributePrincipalImpl extends SimplePrincipal implements Attribute
* @param name the unique identifier for the principal.
*/
public AttributePrincipalImpl(final String name) {
- this(name, Collections. emptyMap());
+ this(name, Collections.emptyMap());
}
/**
@@ -74,8 +78,8 @@ public AttributePrincipalImpl(final String name, final Map attri
* @param proxyRetriever the ProxyRetriever implementation to call back to the CAS server.
*/
public AttributePrincipalImpl(final String name, final String proxyGrantingTicket,
- final ProxyRetriever proxyRetriever) {
- this(name, Collections. emptyMap(), proxyGrantingTicket, proxyRetriever);
+ final ProxyRetriever proxyRetriever) {
+ this(name, Collections.emptyMap(), proxyGrantingTicket, proxyRetriever);
}
/**
@@ -87,7 +91,7 @@ public AttributePrincipalImpl(final String name, final String proxyGrantingTicke
* @param proxyRetriever the ProxyRetriever implementation to call back to the CAS server.
*/
public AttributePrincipalImpl(final String name, final Map attributes,
- final String proxyGrantingTicket, final ProxyRetriever proxyRetriever) {
+ final String proxyGrantingTicket, final ProxyRetriever proxyRetriever) {
super(name);
this.attributes = attributes;
this.proxyGrantingTicket = proxyGrantingTicket;
@@ -96,11 +100,6 @@ public AttributePrincipalImpl(final String name, final Map attri
CommonUtils.assertNotNull(this.attributes, "attributes cannot be null.");
}
- @Override
- public Map getAttributes() {
- return this.attributes;
- }
-
@Override
public String getProxyTicketFor(final String service) {
if (proxyGrantingTicket != null) {
@@ -110,4 +109,18 @@ public String getProxyTicketFor(final String service) {
LOGGER.debug("No ProxyGrantingTicket was supplied, so no Proxy Ticket can be retrieved.");
return null;
}
+
+ @Override
+ public Map getAttributes() {
+ return this.attributes;
+ }
+
+ /**
+ * Returns the proxy granting ticket associated with this principal, if available.
+ *
+ * @return the proxy granting ticket or null
+ */
+ public String getProxyGrantingTicket() {
+ return proxyGrantingTicket;
+ }
}
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/AuthenticationFilter.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/AuthenticationFilter.java
similarity index 77%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/AuthenticationFilter.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/AuthenticationFilter.java
index 3ffebfbaf..af9ed2b55 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/AuthenticationFilter.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/AuthenticationFilter.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,11 +16,12 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
+
+import jakarta.servlet.http.HttpServletRequest;
+import jakarta.servlet.http.HttpServletResponse;
import java.io.IOException;
-import javax.servlet.http.HttpServletRequest;
-import javax.servlet.http.HttpServletResponse;
/**
* Interface to abstract the authentication strategy for redirecting. The traditional method was to always just redirect,
@@ -30,6 +31,7 @@
* @author Scott Battaglia
* @since 3.3.0
*/
+@FunctionalInterface
public interface AuthenticationRedirectStrategy {
/**
@@ -41,6 +43,6 @@ public interface AuthenticationRedirectStrategy {
* @throws IOException the exception to throw if there is some type of error. This will bubble up through the filter.
*/
void redirect(HttpServletRequest request, HttpServletResponse response, String potentialRedirectUrl)
- throws IOException;
+ throws IOException;
}
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/ContainsPatternUrlPatternMatcherStrategy.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/ContainsPatternUrlPatternMatcherStrategy.java
similarity index 91%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/ContainsPatternUrlPatternMatcherStrategy.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/ContainsPatternUrlPatternMatcherStrategy.java
index 0da841a22..aa271cb1d 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/ContainsPatternUrlPatternMatcherStrategy.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/ContainsPatternUrlPatternMatcherStrategy.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,18 +16,18 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
/**
* A pattern matcher that looks inside the url to find the exact pattern specified.
- *
+ *
* @author Misagh Moayyed
* @since 3.3.1
*/
public final class ContainsPatternUrlPatternMatcherStrategy implements UrlPatternMatcherStrategy {
private String pattern;
-
+
@Override
public boolean matches(final String url) {
return url.contains(this.pattern);
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/DefaultAuthenticationRedirectStrategy.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/DefaultAuthenticationRedirectStrategy.java
similarity index 86%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/DefaultAuthenticationRedirectStrategy.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/DefaultAuthenticationRedirectStrategy.java
index 083c92411..370410b6f 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/DefaultAuthenticationRedirectStrategy.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/DefaultAuthenticationRedirectStrategy.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,11 +16,12 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
+
+import jakarta.servlet.http.HttpServletRequest;
+import jakarta.servlet.http.HttpServletResponse;
import java.io.IOException;
-import javax.servlet.http.HttpServletRequest;
-import javax.servlet.http.HttpServletResponse;
/**
* Implementation of the {@link AuthenticationRedirectStrategy} class that preserves the original behavior that existed prior to 3.3.0.
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/DefaultGatewayResolverImpl.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/DefaultGatewayResolverImpl.java
similarity index 80%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/DefaultGatewayResolverImpl.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/DefaultGatewayResolverImpl.java
index b3ca242e5..743a0b036 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/DefaultGatewayResolverImpl.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/DefaultGatewayResolverImpl.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,10 +16,9 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
-import javax.servlet.http.HttpServletRequest;
-import javax.servlet.http.HttpSession;
+import jakarta.servlet.http.HttpServletRequest;
public final class DefaultGatewayResolverImpl implements GatewayResolver {
@@ -27,13 +26,13 @@ public final class DefaultGatewayResolverImpl implements GatewayResolver {
@Override
public boolean hasGatewayedAlready(final HttpServletRequest request, final String serviceUrl) {
- final HttpSession session = request.getSession(false);
+ final var session = request.getSession(false);
if (session == null) {
return false;
}
- final boolean result = session.getAttribute(CONST_CAS_GATEWAY) != null;
+ final var result = session.getAttribute(CONST_CAS_GATEWAY) != null;
return result;
}
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/EntireRegionRegexUrlPatternMatcherStrategy.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/EntireRegionRegexUrlPatternMatcherStrategy.java
similarity index 94%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/EntireRegionRegexUrlPatternMatcherStrategy.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/EntireRegionRegexUrlPatternMatcherStrategy.java
index 1e95064c1..05dd49318 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/EntireRegionRegexUrlPatternMatcherStrategy.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/EntireRegionRegexUrlPatternMatcherStrategy.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,7 +16,7 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
import java.util.regex.Matcher;
import java.util.regex.Pattern;
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/ExactUrlPatternMatcherStrategy.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/ExactUrlPatternMatcherStrategy.java
similarity index 89%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/ExactUrlPatternMatcherStrategy.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/ExactUrlPatternMatcherStrategy.java
index 8500a7d82..41818c26a 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/ExactUrlPatternMatcherStrategy.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/ExactUrlPatternMatcherStrategy.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,12 +16,12 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
/**
* A pattern matcher that produces a successful match if the pattern
* specified matches the given url exactly and equally.
- *
+ *
* @author Misagh Moayyed
* @since 3.3.1
*/
@@ -29,7 +29,8 @@ public final class ExactUrlPatternMatcherStrategy implements UrlPatternMatcherSt
private String pattern;
- public ExactUrlPatternMatcherStrategy() {}
+ public ExactUrlPatternMatcherStrategy() {
+ }
public ExactUrlPatternMatcherStrategy(final String pattern) {
this.setPattern(pattern);
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/FacesCompatibleAuthenticationRedirectStrategy.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/FacesCompatibleAuthenticationRedirectStrategy.java
similarity index 83%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/FacesCompatibleAuthenticationRedirectStrategy.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/FacesCompatibleAuthenticationRedirectStrategy.java
index 51fbb7011..94330d95a 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/FacesCompatibleAuthenticationRedirectStrategy.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/FacesCompatibleAuthenticationRedirectStrategy.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,13 +16,14 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
+
+import org.apereo.cas.client.util.CommonUtils;
+
+import jakarta.servlet.http.HttpServletRequest;
+import jakarta.servlet.http.HttpServletResponse;
import java.io.IOException;
-import java.io.PrintWriter;
-import javax.servlet.http.HttpServletRequest;
-import javax.servlet.http.HttpServletResponse;
-import org.jasig.cas.client.util.CommonUtils;
/**
* Implementation of the redirect strategy that can handle a Faces Ajax request in addition to the standard redirect style.
@@ -43,10 +44,10 @@ public void redirect(final HttpServletRequest request, final HttpServletResponse
response.setContentType("text/xml");
response.setStatus(200);
- final PrintWriter writer = response.getWriter();
+ final var writer = response.getWriter();
writer.write("");
writer.write(String.format("",
- potentialRedirectUrl));
+ potentialRedirectUrl));
} else {
response.sendRedirect(potentialRedirectUrl);
}
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/GatewayResolver.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/GatewayResolver.java
similarity index 90%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/GatewayResolver.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/GatewayResolver.java
index 28ce5afbc..1ade30ef3 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/GatewayResolver.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/GatewayResolver.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,14 +16,14 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
-import javax.servlet.http.HttpServletRequest;
+import jakarta.servlet.http.HttpServletRequest;
/**
* Implementations of this should only have a default constructor if
* you plan on constructing them via the web.xml.
- *
+ *
* @author Scott Battaglia
* @version $Revision$
* @since 1.0
@@ -33,7 +33,7 @@ public interface GatewayResolver {
/**
* Determines if the request has been gatewayed already. Should also do gateway clean up.
- *
+ *
* @param request the Http Servlet Request
* @param serviceUrl the service url
* @return true if yes, false otherwise.
@@ -42,7 +42,7 @@ public interface GatewayResolver {
/**
* Storage the request for gatewaying and return the service url, which can be modified.
- *
+ *
* @param request the HttpServletRequest.
* @param serviceUrl the service url
* @return the potentially modified service url to redirect to
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/RegexUrlPatternMatcherStrategy.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/RegexUrlPatternMatcherStrategy.java
similarity index 94%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/RegexUrlPatternMatcherStrategy.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/RegexUrlPatternMatcherStrategy.java
index d6924504a..48f39b3d3 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/RegexUrlPatternMatcherStrategy.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/RegexUrlPatternMatcherStrategy.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,7 +16,7 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
import java.util.regex.Matcher;
import java.util.regex.Pattern;
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/SimplePrincipal.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/SimplePrincipal.java
similarity index 91%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/SimplePrincipal.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/SimplePrincipal.java
index 299e7c44a..84d6b3a6c 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/SimplePrincipal.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/SimplePrincipal.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,11 +16,13 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
+
+import org.apereo.cas.client.util.CommonUtils;
+import java.io.Serial;
import java.io.Serializable;
import java.security.Principal;
-import org.jasig.cas.client.util.CommonUtils;
/**
* Simple security principal implementation.
@@ -33,6 +35,7 @@
public class SimplePrincipal implements Principal, Serializable {
/** SimplePrincipal.java */
+ @Serial
private static final long serialVersionUID = -5645357206342793145L;
/** The unique identifier for this principal. */
@@ -52,8 +55,8 @@ public final String getName() {
return this.name;
}
- public String toString() {
- return getName();
+ public int hashCode() {
+ return 37 * getName().hashCode();
}
public boolean equals(final Object o) {
@@ -66,7 +69,7 @@ public boolean equals(final Object o) {
}
}
- public int hashCode() {
- return 37 * getName().hashCode();
+ public String toString() {
+ return getName();
}
}
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/UrlPatternMatcherStrategy.java b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/UrlPatternMatcherStrategy.java
similarity index 93%
rename from cas-client-core/src/main/java/org/jasig/cas/client/authentication/UrlPatternMatcherStrategy.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/authentication/UrlPatternMatcherStrategy.java
index ab8112e75..a9b88816c 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/authentication/UrlPatternMatcherStrategy.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/authentication/UrlPatternMatcherStrategy.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,7 +16,8 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.authentication;
+package org.apereo.cas.client.authentication;
+
/**
* Defines an abstraction by which request urls can be matches against a given pattern.
* New instances for all extensions for this strategy interface will be created per
@@ -33,7 +34,7 @@ public interface UrlPatternMatcherStrategy {
* @return true if match is successful
*/
boolean matches(String url);
-
+
/**
* The pattern against which the url is compared
* @param pattern
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/BaseConfigurationStrategy.java b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/BaseConfigurationStrategy.java
similarity index 64%
rename from cas-client-core/src/main/java/org/jasig/cas/client/configuration/BaseConfigurationStrategy.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/configuration/BaseConfigurationStrategy.java
index c1c794a54..be28c4ad6 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/BaseConfigurationStrategy.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/BaseConfigurationStrategy.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,10 +16,11 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.configuration;
+package org.apereo.cas.client.configuration;
+
+import org.apereo.cas.client.util.CommonUtils;
+import org.apereo.cas.client.util.ReflectUtils;
-import org.jasig.cas.client.util.CommonUtils;
-import org.jasig.cas.client.util.ReflectUtils;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
@@ -35,60 +36,51 @@ public abstract class BaseConfigurationStrategy implements ConfigurationStrategy
@Override
public final boolean getBoolean(final ConfigurationKey configurationKey) {
- return getValue(configurationKey, new Parser() {
- @Override
- public Boolean parse(final String value) {
- return CommonUtils.toBoolean(value);
- }
- });
+ return getValue(configurationKey, CommonUtils::toBoolean);
}
@Override
- public final long getLong(final ConfigurationKey configurationKey) {
- return getValue(configurationKey, new Parser() {
- @Override
- public Long parse(final String value) {
- return CommonUtils.toLong(value, configurationKey.getDefaultValue());
- }
- });
+ public final String getString(final ConfigurationKey configurationKey) {
+ return getValue(configurationKey, value -> value);
}
@Override
- public final int getInt(final ConfigurationKey configurationKey) {
- return getValue(configurationKey, new Parser() {
- @Override
- public Integer parse(final String value) {
- return CommonUtils.toInt(value, configurationKey.getDefaultValue());
- }
- });
+ public final long getLong(final ConfigurationKey configurationKey) {
+ return getValue(configurationKey, value -> CommonUtils.toLong(value, configurationKey.getDefaultValue()));
}
@Override
- public final String getString(final ConfigurationKey configurationKey) {
- return getValue(configurationKey, new Parser() {
- @Override
- public String parse(final String value) {
- return value;
- }
- });
+ public final int getInt(final ConfigurationKey configurationKey) {
+ return getValue(configurationKey, value -> CommonUtils.toInt(value, configurationKey.getDefaultValue()));
}
@Override
public Class extends T> getClass(final ConfigurationKey> configurationKey) {
- return getValue(configurationKey, new Parser>() {
- @Override
- public Class extends T> parse(final String value) {
- try {
- return ReflectUtils.loadClass(value);
- } catch (final IllegalArgumentException e) {
- return configurationKey.getDefaultValue();
- }
+ return getValue(configurationKey, value -> {
+ try {
+ return ReflectUtils.loadClass(value);
+ } catch (final IllegalArgumentException e) {
+ return configurationKey.getDefaultValue();
}
});
}
+ /**
+ * Retrieve the String value for this key. Returns null if there is no value.
+ *
+ * @param configurationKey the key to retrieve. MUST NOT BE NULL.
+ * @return the String if its found, null otherwise.
+ */
+ protected abstract String get(ConfigurationKey configurationKey);
+
+ @FunctionalInterface
+ private interface Parser {
+
+ T parse(String value);
+ }
+
private T getValue(final ConfigurationKey configurationKey, final Parser parser) {
- final String value = getWithCheck(configurationKey);
+ final var value = getWithCheck(configurationKey);
if (CommonUtils.isBlank(value)) {
logger.trace("No value found for property {}, returning default {}", configurationKey.getName(), configurationKey.getDefaultValue());
@@ -105,17 +97,4 @@ private String getWithCheck(final ConfigurationKey configurationKey) {
return get(configurationKey);
}
-
- /**
- * Retrieve the String value for this key. Returns null if there is no value.
- *
- * @param configurationKey the key to retrieve. MUST NOT BE NULL.
- * @return the String if its found, null otherwise.
- */
- protected abstract String get(ConfigurationKey configurationKey);
-
- private interface Parser {
-
- T parse(String value);
- }
}
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/ConfigurationKey.java b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationKey.java
similarity index 92%
rename from cas-client-core/src/main/java/org/jasig/cas/client/configuration/ConfigurationKey.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationKey.java
index 1e0eebeef..396f76fad 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/ConfigurationKey.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationKey.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,9 +16,9 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.configuration;
+package org.apereo.cas.client.configuration;
-import org.jasig.cas.client.util.CommonUtils;
+import org.apereo.cas.client.util.CommonUtils;
/**
* Holder class to represent a particular configuration key and its optional default value.
@@ -60,7 +60,7 @@ public String getName() {
public E getDefaultValue() {
return this.defaultValue;
}
-
+
@Override
public String toString() {
return getName();
diff --git a/cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationKeys.java b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationKeys.java
new file mode 100644
index 000000000..5468a6384
--- /dev/null
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationKeys.java
@@ -0,0 +1,89 @@
+/**
+ * Licensed to Apereo under one or more contributor license
+ * agreements. See the NOTICE file distributed with this work
+ * for additional information regarding copyright ownership.
+ * Apereo licenses this file to you under the Apache License,
+ * Version 2.0 (the "License"); you may not use this file
+ * except in compliance with the License. You may obtain a
+ * copy of the License at the following location:
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+package org.apereo.cas.client.configuration;
+
+import org.apereo.cas.client.Protocol;
+import org.apereo.cas.client.authentication.AuthenticationRedirectStrategy;
+import org.apereo.cas.client.authentication.DefaultGatewayResolverImpl;
+import org.apereo.cas.client.authentication.GatewayResolver;
+import org.apereo.cas.client.proxy.ProxyGrantingTicketStorage;
+import org.apereo.cas.client.proxy.ProxyGrantingTicketStorageImpl;
+import org.apereo.cas.client.validation.Cas20ServiceTicketValidator;
+
+import javax.net.ssl.HostnameVerifier;
+
+/**
+ * Holder interface for all known configuration keys.
+ *
+ * @author Scott Battaglia
+ * @since 3.4.0
+ */
+public interface ConfigurationKeys {
+
+ ConfigurationKey ARTIFACT_PARAMETER_NAME = new ConfigurationKey<>("artifactParameterName", Protocol.CAS2.getArtifactParameterName());
+ ConfigurationKey SERVER_NAME = new ConfigurationKey<>("serverName", null);
+ ConfigurationKey SERVICE = new ConfigurationKey<>("service");
+ ConfigurationKey RENEW = new ConfigurationKey<>("renew", Boolean.FALSE);
+ ConfigurationKey LOGOUT_PARAMETER_NAME = new ConfigurationKey<>("logoutParameterName", "logoutRequest");
+ ConfigurationKey ARTIFACT_PARAMETER_OVER_POST = new ConfigurationKey<>("artifactParameterOverPost", Boolean.FALSE);
+ ConfigurationKey EAGERLY_CREATE_SESSIONS = new ConfigurationKey<>("eagerlyCreateSessions", Boolean.TRUE);
+ ConfigurationKey ENCODE_SERVICE_URL = new ConfigurationKey<>("encodeServiceUrl", Boolean.TRUE);
+ ConfigurationKey SSL_CONFIG_FILE = new ConfigurationKey<>("sslConfigFile", null);
+ ConfigurationKey ROLE_ATTRIBUTE = new ConfigurationKey<>("roleAttribute", null);
+ ConfigurationKey IGNORE_CASE = new ConfigurationKey<>("ignoreCase", Boolean.FALSE);
+ ConfigurationKey CAS_SERVER_LOGIN_URL = new ConfigurationKey<>("casServerLoginUrl", null);
+ ConfigurationKey GATEWAY = new ConfigurationKey<>("gateway", Boolean.FALSE);
+ ConfigurationKey METHOD = new ConfigurationKey<>("method", null);
+ ConfigurationKey> AUTHENTICATION_REDIRECT_STRATEGY_CLASS =
+ new ConfigurationKey<>("authenticationRedirectStrategyClass", null);
+ ConfigurationKey> GATEWAY_STORAGE_CLASS =
+ new ConfigurationKey<>("gatewayStorageClass", DefaultGatewayResolverImpl.class);
+ ConfigurationKey CAS_SERVER_URL_PREFIX = new ConfigurationKey<>("casServerUrlPrefix", null);
+ ConfigurationKey ENCODING = new ConfigurationKey<>("encoding", null);
+ ConfigurationKey TOLERANCE = new ConfigurationKey<>("tolerance", 1000L);
+ ConfigurationKey PRIVATE_KEY_PATH = new ConfigurationKey<>("privateKeyPath", null);
+ ConfigurationKey PRIVATE_KEY_ALGORITHM = new ConfigurationKey<>("privateKeyAlgorithm", "RSA");
+
+ /**
+ * @deprecated As of 3.4. This constant is not used by the client and will
+ * be removed in future versions.
+ */
+ @Deprecated
+ ConfigurationKey DISABLE_XML_SCHEMA_VALIDATION = new ConfigurationKey<>("disableXmlSchemaValidation", Boolean.FALSE);
+ ConfigurationKey IGNORE_PATTERN = new ConfigurationKey<>("ignorePattern", null);
+ ConfigurationKey IGNORE_URL_PATTERN_TYPE = new ConfigurationKey<>("ignoreUrlPatternType", "REGEX");
+ ConfigurationKey> HOSTNAME_VERIFIER = new ConfigurationKey<>("hostnameVerifier", null);
+ ConfigurationKey HOSTNAME_VERIFIER_CONFIG = new ConfigurationKey<>("hostnameVerifierConfig", null);
+ ConfigurationKey EXCEPTION_ON_VALIDATION_FAILURE = new ConfigurationKey<>("exceptionOnValidationFailure", Boolean.TRUE);
+ ConfigurationKey REDIRECT_AFTER_VALIDATION = new ConfigurationKey<>("redirectAfterValidation", Boolean.TRUE);
+ ConfigurationKey USE_SESSION = new ConfigurationKey<>("useSession", Boolean.TRUE);
+ ConfigurationKey SECRET_KEY = new ConfigurationKey<>("secretKey", null);
+ ConfigurationKey CIPHER_ALGORITHM = new ConfigurationKey<>("cipherAlgorithm", "DESede");
+ ConfigurationKey PROXY_RECEPTOR_URL = new ConfigurationKey<>("proxyReceptorUrl", null);
+ ConfigurationKey> PROXY_GRANTING_TICKET_STORAGE_CLASS =
+ new ConfigurationKey<>("proxyGrantingTicketStorageClass", ProxyGrantingTicketStorageImpl.class);
+ ConfigurationKey MILLIS_BETWEEN_CLEAN_UPS = new ConfigurationKey<>("millisBetweenCleanUps", 60000);
+ ConfigurationKey ACCEPT_ANY_PROXY = new ConfigurationKey<>("acceptAnyProxy", Boolean.FALSE);
+ ConfigurationKey ALLOWED_PROXY_CHAINS = new ConfigurationKey<>("allowedProxyChains", null);
+ ConfigurationKey> TICKET_VALIDATOR_CLASS = new ConfigurationKey<>("ticketValidatorClass", null);
+ ConfigurationKey PROXY_CALLBACK_URL = new ConfigurationKey<>("proxyCallbackUrl", null);
+ ConfigurationKey RELAY_STATE_PARAMETER_NAME = new ConfigurationKey<>("relayStateParameterName", "RelayState");
+ ConfigurationKey LOGOUT_CALLBACK_PATH = new ConfigurationKey<>("logoutCallbackPath", null);
+ ConfigurationKey JSONP_CALLBACK_PARAMETER_NAME = new ConfigurationKey<>("jsonpCallbackParameterName", "callback");
+}
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/ConfigurationStrategy.java b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationStrategy.java
similarity index 94%
rename from cas-client-core/src/main/java/org/jasig/cas/client/configuration/ConfigurationStrategy.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationStrategy.java
index 5b6a5dc99..525397d01 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/ConfigurationStrategy.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationStrategy.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,10 +16,10 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.configuration;
+package org.apereo.cas.client.configuration;
-import javax.servlet.Filter;
-import javax.servlet.FilterConfig;
+import jakarta.servlet.Filter;
+import jakarta.servlet.FilterConfig;
/**
* Abstraction to allow for pluggable methods for retrieving filter configuration.
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/ConfigurationStrategyName.java b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationStrategyName.java
similarity index 86%
rename from cas-client-core/src/main/java/org/jasig/cas/client/configuration/ConfigurationStrategyName.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationStrategyName.java
index a8326c109..a5da2b6f9 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/ConfigurationStrategyName.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/ConfigurationStrategyName.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,9 +16,10 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.configuration;
+package org.apereo.cas.client.configuration;
+
+import org.apereo.cas.client.util.CommonUtils;
-import org.jasig.cas.client.util.CommonUtils;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
@@ -43,7 +44,7 @@ private ConfigurationStrategyName(final Class extends ConfigurationStrategy> c
}
/**
- * Static helper method that will resolve a simple string to either an enum value or a {@link org.jasig.cas.client.configuration.ConfigurationStrategy} class.
+ * Static helper method that will resolve a simple string to either an enum value or a {@link ConfigurationStrategy} class.
*
* @param value the value to attempt to resolve.
* @return the underlying class that this maps to (either via simple name or fully qualified class name).
@@ -53,19 +54,19 @@ public static Class extends ConfigurationStrategy> resolveToConfigurationStrat
return DEFAULT.configurationStrategyClass;
}
- for (final ConfigurationStrategyName csn : values()) {
+ for (final var csn : values()) {
if (csn.name().equalsIgnoreCase(value)) {
return csn.configurationStrategyClass;
}
}
try {
- final Class> clazz = Class.forName(value);
+ final var clazz = Class.forName(value);
if (ConfigurationStrategy.class.isAssignableFrom(clazz)) {
return (Class extends ConfigurationStrategy>) clazz;
}
- } catch (final ClassNotFoundException e) {
+ } catch (final ClassNotFoundException e) {
LOGGER.error("Unable to locate strategy {} by name or class name. Using default strategy instead.", value, e);
}
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/JndiConfigurationStrategyImpl.java b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/JndiConfigurationStrategyImpl.java
similarity index 81%
rename from cas-client-core/src/main/java/org/jasig/cas/client/configuration/JndiConfigurationStrategyImpl.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/configuration/JndiConfigurationStrategyImpl.java
index 32ef7296a..2baf19c93 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/JndiConfigurationStrategyImpl.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/JndiConfigurationStrategyImpl.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,14 +16,15 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.configuration;
+package org.apereo.cas.client.configuration;
+
+import org.apereo.cas.client.util.CommonUtils;
-import org.jasig.cas.client.util.CommonUtils;
+import jakarta.servlet.Filter;
+import jakarta.servlet.FilterConfig;
import javax.naming.InitialContext;
import javax.naming.NamingException;
-import javax.servlet.Filter;
-import javax.servlet.FilterConfig;
/**
* Loads configuration information from JNDI, using the defaultValue if it can't.
@@ -49,21 +50,31 @@ public JndiConfigurationStrategyImpl(final String environmentPrefix) {
this.environmentPrefix = environmentPrefix;
}
+ @Override
+ public final void init(final FilterConfig filterConfig, final Class extends Filter> clazz) {
+ this.simpleFilterName = clazz.getSimpleName();
+ try {
+ this.context = new InitialContext();
+ } catch (final NamingException e) {
+ logger.error("Unable to create InitialContext. No properties can be loaded via JNDI.", e);
+ }
+ }
+
@Override
protected final String get(final ConfigurationKey configurationKey) {
if (context == null) {
return null;
}
- final String propertyName = configurationKey.getName();
- final String filterValue = loadFromContext(context, this.environmentPrefix + this.simpleFilterName + "/" + propertyName);
+ final var propertyName = configurationKey.getName();
+ final var filterValue = loadFromContext(context, this.environmentPrefix + this.simpleFilterName + "/" + propertyName);
if (CommonUtils.isNotBlank(filterValue)) {
logger.info("Property [{}] loaded from JNDI Filter Specific Property with value [{}]", propertyName, filterValue);
return filterValue;
}
- final String rootValue = loadFromContext(context, this.environmentPrefix + propertyName);
+ final var rootValue = loadFromContext(context, this.environmentPrefix + propertyName);
if (CommonUtils.isNotBlank(rootValue)) {
logger.info("Property [{}] loaded from JNDI with value [{}]", propertyName, rootValue);
@@ -73,22 +84,11 @@ protected final String get(final ConfigurationKey configurationKey) {
return null;
}
- private String loadFromContext(final InitialContext context, final String path) {
+ private static String loadFromContext(final InitialContext context, final String path) {
try {
return (String) context.lookup(path);
} catch (final NamingException e) {
return null;
}
}
-
-
- @Override
- public final void init(final FilterConfig filterConfig, final Class extends Filter> clazz) {
- this.simpleFilterName = clazz.getSimpleName();
- try {
- this.context = new InitialContext();
- } catch (final NamingException e) {
- logger.error("Unable to create InitialContext. No properties can be loaded via JNDI.", e);
- }
- }
}
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/LegacyConfigurationStrategyImpl.java b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/LegacyConfigurationStrategyImpl.java
similarity index 74%
rename from cas-client-core/src/main/java/org/jasig/cas/client/configuration/LegacyConfigurationStrategyImpl.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/configuration/LegacyConfigurationStrategyImpl.java
index 22b31c591..0f5badadf 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/LegacyConfigurationStrategyImpl.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/LegacyConfigurationStrategyImpl.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,16 +16,16 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.configuration;
+package org.apereo.cas.client.configuration;
-import org.jasig.cas.client.util.CommonUtils;
+import org.apereo.cas.client.util.CommonUtils;
-import javax.servlet.Filter;
-import javax.servlet.FilterConfig;
+import jakarta.servlet.Filter;
+import jakarta.servlet.FilterConfig;
/**
- * Replicates the original behavior by checking the {@link org.jasig.cas.client.configuration.WebXmlConfigurationStrategyImpl} first, and then
- * the {@link org.jasig.cas.client.configuration.JndiConfigurationStrategyImpl} before using the defaultValue.
+ * Replicates the original behavior by checking the {@link WebXmlConfigurationStrategyImpl} first, and then
+ * the {@link JndiConfigurationStrategyImpl} before using the defaultValue.
*
* @author Scott Battaglia
* @since 3.4.0
@@ -44,7 +44,7 @@ public void init(final FilterConfig filterConfig, final Class extends Filter>
@Override
protected String get(final ConfigurationKey key) {
- final String value1 = this.webXmlConfigurationStrategy.get(key);
+ final var value1 = this.webXmlConfigurationStrategy.get(key);
if (CommonUtils.isNotBlank(value1)) {
return value1;
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/PropertiesConfigurationStrategyImpl.java b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/PropertiesConfigurationStrategyImpl.java
similarity index 74%
rename from cas-client-core/src/main/java/org/jasig/cas/client/configuration/PropertiesConfigurationStrategyImpl.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/configuration/PropertiesConfigurationStrategyImpl.java
index c88c75d41..5d4830429 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/PropertiesConfigurationStrategyImpl.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/PropertiesConfigurationStrategyImpl.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,14 +16,15 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.configuration;
+package org.apereo.cas.client.configuration;
-import org.jasig.cas.client.util.CommonUtils;
+import org.apereo.cas.client.util.CommonUtils;
+
+import jakarta.servlet.Filter;
+import jakarta.servlet.FilterConfig;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
-import javax.servlet.Filter;
-import javax.servlet.FilterConfig;
import java.io.FileInputStream;
import java.io.IOException;
import java.util.Properties;
@@ -47,41 +48,41 @@ public final class PropertiesConfigurationStrategyImpl extends BaseConfiguration
private static final Logger LOGGER = LoggerFactory.getLogger(PropertiesConfigurationStrategyImpl.class);
- private String simpleFilterName;
-
private final Properties properties = new Properties();
- @Override
- protected String get(final ConfigurationKey configurationKey) {
- final String property = configurationKey.getName();
- final String filterSpecificProperty = this.simpleFilterName + "." + property;
-
- final String filterSpecificValue = this.properties.getProperty(filterSpecificProperty);
-
- if (CommonUtils.isNotEmpty(filterSpecificValue)) {
- return filterSpecificValue;
- }
-
- return this.properties.getProperty(property);
- }
+ private String simpleFilterName;
@Override
public void init(final FilterConfig filterConfig, final Class extends Filter> filterClazz) {
this.simpleFilterName = filterClazz.getSimpleName();
- final String fileLocationFromFilterConfig = filterConfig.getInitParameter(CONFIGURATION_FILE_LOCATION);
- final boolean filterConfigFileLoad = loadPropertiesFromFile(fileLocationFromFilterConfig);
+ final var fileLocationFromFilterConfig = filterConfig.getInitParameter(CONFIGURATION_FILE_LOCATION);
+ final var filterConfigFileLoad = loadPropertiesFromFile(fileLocationFromFilterConfig);
if (!filterConfigFileLoad) {
- final String fileLocationFromServletConfig = filterConfig.getServletContext().getInitParameter(CONFIGURATION_FILE_LOCATION);
- final boolean servletContextFileLoad = loadPropertiesFromFile(fileLocationFromServletConfig);
+ final var fileLocationFromServletConfig = filterConfig.getServletContext().getInitParameter(CONFIGURATION_FILE_LOCATION);
+ final var servletContextFileLoad = loadPropertiesFromFile(fileLocationFromServletConfig);
if (!servletContextFileLoad) {
- final boolean defaultConfigFileLoaded = loadPropertiesFromFile(DEFAULT_CONFIGURATION_FILE_LOCATION);
+ final var defaultConfigFileLoaded = loadPropertiesFromFile(DEFAULT_CONFIGURATION_FILE_LOCATION);
CommonUtils.assertTrue(defaultConfigFileLoaded, "unable to load properties to configure CAS client");
}
}
}
+ @Override
+ protected String get(final ConfigurationKey configurationKey) {
+ final var property = configurationKey.getName();
+ final var filterSpecificProperty = this.simpleFilterName + "." + property;
+
+ final var filterSpecificValue = this.properties.getProperty(filterSpecificProperty);
+
+ if (CommonUtils.isNotEmpty(filterSpecificValue)) {
+ return filterSpecificValue;
+ }
+
+ return this.properties.getProperty(property);
+ }
+
private boolean loadPropertiesFromFile(final String file) {
if (CommonUtils.isEmpty(file)) {
return false;
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/SystemPropertiesConfigurationStrategyImpl.java b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/SystemPropertiesConfigurationStrategyImpl.java
similarity index 87%
rename from cas-client-core/src/main/java/org/jasig/cas/client/configuration/SystemPropertiesConfigurationStrategyImpl.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/configuration/SystemPropertiesConfigurationStrategyImpl.java
index c8f1ba6d0..f224c139e 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/SystemPropertiesConfigurationStrategyImpl.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/SystemPropertiesConfigurationStrategyImpl.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,10 +16,10 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.configuration;
+package org.apereo.cas.client.configuration;
-import javax.servlet.Filter;
-import javax.servlet.FilterConfig;
+import jakarta.servlet.Filter;
+import jakarta.servlet.FilterConfig;
/**
* Load all configuration from system properties.
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/WebXmlConfigurationStrategyImpl.java b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/WebXmlConfigurationStrategyImpl.java
similarity index 76%
rename from cas-client-core/src/main/java/org/jasig/cas/client/configuration/WebXmlConfigurationStrategyImpl.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/configuration/WebXmlConfigurationStrategyImpl.java
index d9dbc00fa..82f51acce 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/configuration/WebXmlConfigurationStrategyImpl.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/configuration/WebXmlConfigurationStrategyImpl.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,15 +16,15 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.configuration;
+package org.apereo.cas.client.configuration;
-import org.jasig.cas.client.util.CommonUtils;
+import org.apereo.cas.client.util.CommonUtils;
-import javax.servlet.Filter;
-import javax.servlet.FilterConfig;
+import jakarta.servlet.Filter;
+import jakarta.servlet.FilterConfig;
/**
- * Implementation of the {@link org.jasig.cas.client.configuration.ConfigurationStrategy} that first checks the {@link javax.servlet.FilterConfig} and
+ * Implementation of the {@link ConfigurationStrategy} that first checks the {@link javax.servlet.FilterConfig} and
* then checks the {@link javax.servlet.ServletContext}, ultimately falling back to the defaultValue.
*
* @author Scott Battaglia
@@ -34,9 +34,14 @@ public final class WebXmlConfigurationStrategyImpl extends BaseConfigurationStra
private FilterConfig filterConfig;
+ @Override
+ public void init(final FilterConfig filterConfig, final Class extends Filter> clazz) {
+ this.filterConfig = filterConfig;
+ }
+
@Override
protected String get(final ConfigurationKey configurationKey) {
- final String value = this.filterConfig.getInitParameter(configurationKey.getName());
+ final var value = this.filterConfig.getInitParameter(configurationKey.getName());
if (CommonUtils.isNotBlank(value)) {
CommonUtils.assertFalse(ConfigurationKeys.RENEW.equals(configurationKey), "Renew MUST be specified via context parameter or JNDI environment to avoid misconfiguration.");
@@ -44,19 +49,14 @@ protected String get(final ConfigurationKey configurationKey) {
return value;
}
- final String value2 = filterConfig.getServletContext().getInitParameter(configurationKey.getName());
+ final var value2 = filterConfig.getServletContext().getInitParameter(configurationKey.getName());
if (CommonUtils.isNotBlank(value2)) {
logger.info("Property [{}] loaded from ServletContext.getInitParameter with value [{}]", configurationKey,
- value2);
+ value2);
return value2;
}
return null;
}
-
- @Override
- public void init(final FilterConfig filterConfig, final Class extends Filter> clazz) {
- this.filterConfig = filterConfig;
- }
}
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/jaas/AssertionPrincipal.java b/cas-client-core/src/main/java/org/apereo/cas/client/jaas/AssertionPrincipal.java
similarity index 87%
rename from cas-client-core/src/main/java/org/jasig/cas/client/jaas/AssertionPrincipal.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/jaas/AssertionPrincipal.java
index bf46e371e..ff27d6203 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/jaas/AssertionPrincipal.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/jaas/AssertionPrincipal.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,11 +16,13 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.jaas;
+package org.apereo.cas.client.jaas;
+
+import org.apereo.cas.client.authentication.SimplePrincipal;
+import org.apereo.cas.client.validation.Assertion;
+import java.io.Serial;
import java.io.Serializable;
-import org.jasig.cas.client.authentication.SimplePrincipal;
-import org.jasig.cas.client.validation.Assertion;
/**
* Principal implementation that contains the CAS ticket validation assertion.
@@ -33,6 +35,7 @@
public class AssertionPrincipal extends SimplePrincipal implements Serializable {
/** AssertionPrincipal.java */
+ @Serial
private static final long serialVersionUID = 2288520214366461693L;
/** CAS assertion describing authenticated state */
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/jaas/CasLoginModule.java b/cas-client-core/src/main/java/org/apereo/cas/client/jaas/CasLoginModule.java
similarity index 72%
rename from cas-client-core/src/main/java/org/jasig/cas/client/jaas/CasLoginModule.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/jaas/CasLoginModule.java
index 6868e66a1..05b6b6eac 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/jaas/CasLoginModule.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/jaas/CasLoginModule.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,29 +16,38 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.jaas;
+package org.apereo.cas.client.jaas;
+
+import org.apereo.cas.client.authentication.SimplePrincipal;
+import org.apereo.cas.client.util.CommonUtils;
+import org.apereo.cas.client.util.ReflectUtils;
+import org.apereo.cas.client.validation.Assertion;
+import org.apereo.cas.client.validation.TicketValidator;
+
+import org.slf4j.Logger;
+import org.slf4j.LoggerFactory;
+
+import javax.security.auth.Subject;
+import javax.security.auth.callback.Callback;
+import javax.security.auth.callback.CallbackHandler;
+import javax.security.auth.callback.NameCallback;
+import javax.security.auth.callback.PasswordCallback;
+import javax.security.auth.callback.UnsupportedCallbackException;
+import javax.security.auth.login.LoginException;
+import javax.security.auth.spi.LoginModule;
-import java.beans.BeanInfo;
import java.beans.IntrospectionException;
import java.beans.Introspector;
import java.beans.PropertyDescriptor;
import java.io.IOException;
import java.security.Principal;
-import java.security.acl.Group;
-import java.util.*;
+import java.util.Arrays;
+import java.util.Calendar;
+import java.util.Collection;
+import java.util.HashMap;
+import java.util.HashSet;
+import java.util.Map;
import java.util.concurrent.TimeUnit;
-import javax.security.auth.Subject;
-import javax.security.auth.callback.*;
-import javax.security.auth.login.LoginException;
-import javax.security.auth.spi.LoginModule;
-import org.jasig.cas.client.authentication.SimpleGroup;
-import org.jasig.cas.client.authentication.SimplePrincipal;
-import org.jasig.cas.client.util.CommonUtils;
-import org.jasig.cas.client.util.ReflectUtils;
-import org.jasig.cas.client.validation.Assertion;
-import org.jasig.cas.client.validation.TicketValidator;
-import org.slf4j.Logger;
-import org.slf4j.LoggerFactory;
/**
* JAAS login module that delegates to a CAS {@link TicketValidator} component
@@ -46,7 +55,7 @@
* data including NetID and principal attributes. The module expects to be provided
* with the CAS ticket (required) and service (optional) parameters via
* {@link PasswordCallback} and {@link NameCallback}, respectively, by the
- * {@link CallbackHandler} that is part of the JAAS framework in which the servlet
+ * {@link CallbackHandler} that is part of the JAAS framework in which the servlet
* resides.
*
*
@@ -83,14 +92,13 @@
* Sample jaas.config file entry for this module:
*
@@ -98,10 +106,11 @@
* @author Marvin S. Addison
* @version $Revision$ $Date$
* @since 3.1.11
- *
*/
public class CasLoginModule implements LoginModule {
- /** Constant for login name stored in shared state. */
+ /**
+ * Constant for login name stored in shared state.
+ */
public static final String LOGIN_NAME = "javax.security.auth.login.name";
/**
@@ -123,7 +132,9 @@ public class CasLoginModule implements LoginModule {
*/
public static final int DEFAULT_CACHE_TIMEOUT = 480;
- /** Default assertion cache timeout unit is minutes. */
+ /**
+ * Default assertion cache timeout unit is minutes.
+ */
public static final TimeUnit DEFAULT_CACHE_TIMEOUT_UNIT = TimeUnit.MINUTES;
/**
@@ -132,76 +143,131 @@ public class CasLoginModule implements LoginModule {
* CAS tickets are one-time-use, a cached assertion must be provided on
* re-authentication.
*/
- protected static final Map ASSERTION_CACHE = new HashMap();
+ protected static final Map ASSERTION_CACHE = new HashMap<>();
- /** Logger instance */
+ /**
+ * Logger instance
+ */
protected final Logger logger = LoggerFactory.getLogger(getClass());
- /** JAAS authentication subject */
+ /**
+ * Names of attributes in the CAS assertion that should be used for role data
+ */
+ protected final Collection roleAttributeNames = new HashSet<>();
+
+ /**
+ * JAAS authentication subject
+ */
protected Subject subject;
- /** JAAS callback handler */
+ /**
+ * JAAS callback handler
+ */
protected CallbackHandler callbackHandler;
- /** CAS ticket validator */
+ /**
+ * CAS ticket validator
+ */
protected TicketValidator ticketValidator;
- /** CAS service parameter used if no service is provided via TextCallback on login */
+ /**
+ * CAS service parameter used if no service is provided via TextCallback on login
+ */
protected String service;
- /** CAS assertion */
+ /**
+ * CAS assertion
+ */
protected Assertion assertion;
- /** CAS ticket credential */
+ /**
+ * CAS ticket credential
+ */
protected TicketCredential ticket;
- /** Login module shared state */
+ /**
+ * Login module shared state
+ */
protected Map sharedState;
- /** Roles to be added to all authenticated principals by default */
+ /**
+ * Roles to be added to all authenticated principals by default
+ */
protected String[] defaultRoles;
- /** Names of attributes in the CAS assertion that should be used for role data */
- protected final Set roleAttributeNames = new HashSet();
-
- /** Name of JAAS Group containing caller principal */
+ /**
+ * Name of JAAS Group containing caller principal
+ */
protected String principalGroupName = DEFAULT_PRINCIPAL_GROUP_NAME;
- /** Name of JAAS Group containing role data */
+ /**
+ * Name of JAAS Group containing role data
+ */
protected String roleGroupName = DEFAULT_ROLE_GROUP_NAME;
- /** Enables or disable assertion caching */
+ /**
+ * Enables or disable assertion caching
+ */
protected boolean cacheAssertions;
- /** Assertion cache timeout in minutes */
+ /**
+ * Assertion cache timeout in minutes
+ */
protected int cacheTimeout = DEFAULT_CACHE_TIMEOUT;
- /** Units of cache timeout. */
+ /**
+ * Units of cache timeout.
+ */
protected TimeUnit cacheTimeoutUnit = DEFAULT_CACHE_TIMEOUT_UNIT;
+ /**
+ * Attempts to do simple type conversion from a string value to the type expected
+ * by the given property.
+ *
+ * Currently only conversion to int, long, and boolean are supported.
+ *
+ * @param pd Property descriptor of target property to set.
+ * @param value Property value as a string.
+ * @return Value converted to type expected by property if a conversion strategy exists.
+ */
+ private static Object convertIfNecessary(final PropertyDescriptor pd, final String value) {
+ if (String.class.equals(pd.getPropertyType())) {
+ return value;
+ } else if (boolean.class.equals(pd.getPropertyType())) {
+ return Boolean.valueOf(value);
+ } else if (int.class.equals(pd.getPropertyType())) {
+ return new Integer(value);
+ } else if (long.class.equals(pd.getPropertyType())) {
+ return new Long(value);
+ } else {
+ throw new IllegalArgumentException("No conversion strategy exists for property " + pd.getName()
+ + " of type " + pd.getPropertyType());
+ }
+ }
+
/**
* Initializes the CAS login module.
*
* @param subject Authentication subject.
* @param handler Callback handler.
- * @param state Shared state map.
+ * @param state Shared state map.
* @param options Login module options. The following are supported:
- *
- *
service - CAS service URL used for service ticket validation.
- *
ticketValidatorClass - fully-qualified class name of service ticket validator component.
- *
defaultRoles (optional) - comma-delimited list of roles to be added to all authenticated principals.
- *
roleAttributeNames (optional) - comma-delimited list of attributes in the CAS assertion that contain role data.
- *
principalGroupName (optional) - name of JAAS Group containing caller principal.
- *
roleGroupName (optional) - name of JAAS Group containing role data
- *
cacheAssertions (optional) - whether or not to cache assertions.
- * Some JAAS providers attempt to reauthenticate users after an indeterminate
- * period of time. Since the credential used for authentication is a CAS ticket,
- * which by default are single use, reauthentication fails. Assertion caching addresses this
- * behavior.
- *
cacheTimeout (optional) - assertion cache timeout in minutes.
- *
cacheTimeoutUnit (optional) - Assertion cache timeout unit. Must be one of {@link TimeUnit} enumeration
- * names, e.g. DAYS, HOURS, MINUTES, SECONDS, MILLISECONDS. Default unit is MINUTES.
- *
+ *
+ *
service - CAS service URL used for service ticket validation.
+ *
ticketValidatorClass - fully-qualified class name of service ticket validator component.
+ *
defaultRoles (optional) - comma-delimited list of roles to be added to all authenticated principals.
+ *
roleAttributeNames (optional) - comma-delimited list of attributes in the CAS assertion that contain role data.
+ *
principalGroupName (optional) - name of JAAS Group containing caller principal.
+ *
roleGroupName (optional) - name of JAAS Group containing role data
+ *
cacheAssertions (optional) - whether or not to cache assertions.
+ * Some JAAS providers attempt to reauthenticate users after an indeterminate
+ * period of time. Since the credential used for authentication is a CAS ticket,
+ * which by default are single use, reauthentication fails. Assertion caching addresses this
+ * behavior.
+ *
cacheTimeout (optional) - assertion cache timeout in minutes.
+ *
cacheTimeoutUnit (optional) - Assertion cache timeout unit. Must be one of {@link TimeUnit} enumeration
+ * names, e.g. DAYS, HOURS, MINUTES, SECONDS, MILLISECONDS. Default unit is MINUTES.
+ *
*/
@Override
public final void initialize(final Subject subject, final CallbackHandler handler, final Map state,
@@ -211,11 +277,11 @@ public final void initialize(final Subject subject, final CallbackHandler handle
this.callbackHandler = handler;
this.subject = subject;
this.sharedState = (Map) state;
- this.sharedState = new HashMap(state);
+ this.sharedState = new HashMap<>(state);
String ticketValidatorClass = null;
- for (final String key : options.keySet()) {
+ for (final var key : options.keySet()) {
logger.trace("Processing option {}", key);
if ("service".equals(key)) {
this.service = (String) options.get(key);
@@ -224,14 +290,14 @@ public final void initialize(final Subject subject, final CallbackHandler handle
ticketValidatorClass = (String) options.get(key);
logger.debug("Set ticketValidatorClass={}", ticketValidatorClass);
} else if ("defaultRoles".equals(key)) {
- final String roles = (String) options.get(key);
+ final var roles = (String) options.get(key);
logger.trace("Got defaultRoles value {}", roles);
this.defaultRoles = roles.split(",\\s*");
logger.debug("Set defaultRoles={}", Arrays.asList(this.defaultRoles));
} else if ("roleAttributeNames".equals(key)) {
- final String attrNames = (String) options.get(key);
+ final var attrNames = (String) options.get(key);
logger.trace("Got roleAttributeNames value {}", attrNames);
- final String[] attributes = attrNames.split(",\\s*");
+ final var attributes = attrNames.split(",\\s*");
this.roleAttributeNames.addAll(Arrays.asList(attributes));
logger.debug("Set roleAttributeNames={}", this.roleAttributeNames);
} else if ("principalGroupName".equals(key)) {
@@ -260,24 +326,6 @@ public final void initialize(final Subject subject, final CallbackHandler handle
this.ticketValidator = createTicketValidator(ticketValidatorClass, options);
}
- /**
- * Operations to perform before doing login.
- *
- * @return true if you'd like login to continue, false otherwise.
- */
- protected boolean preLogin() {
- return true;
- }
-
- /**
- * This occurs after logout is processed.
- *
- * @param result the result from the login attempt.
- */
- protected void postLogin(final boolean result) {
- // template method
- }
-
@Override
public final boolean login() throws LoginException {
logger.debug("Performing login.");
@@ -287,25 +335,25 @@ public final boolean login() throws LoginException {
return false;
}
- final NameCallback serviceCallback = new NameCallback("service");
- final PasswordCallback ticketCallback = new PasswordCallback("ticket", false);
- boolean result = false;
+ final var serviceCallback = new NameCallback("service");
+ final var ticketCallback = new PasswordCallback("ticket", false);
+ var result = false;
try {
try {
- this.callbackHandler.handle(new Callback[] { ticketCallback, serviceCallback });
+ this.callbackHandler.handle(new Callback[]{ticketCallback, serviceCallback});
} catch (final IOException e) {
logger.info("Login failed due to IO exception in callback handler", e);
throw (LoginException) new LoginException("IO exception in callback handler: " + e).initCause(e);
} catch (final UnsupportedCallbackException e) {
logger.info("Login failed due to unsupported callback", e);
throw (LoginException) new LoginException(
- "Callback handler does not support PasswordCallback and TextInputCallback.").initCause(e);
+ "Callback handler does not support PasswordCallback and TextInputCallback.").initCause(e);
}
if (ticketCallback.getPassword() != null) {
this.ticket = new TicketCredential(new String(ticketCallback.getPassword()));
- final String service = CommonUtils.isNotBlank(serviceCallback.getName()) ? serviceCallback.getName()
- : this.service;
+ final var service = CommonUtils.isNotBlank(serviceCallback.getName()) ? serviceCallback.getName()
+ : this.service;
if (this.cacheAssertions) {
this.assertion = ASSERTION_CACHE.get(ticket);
@@ -319,11 +367,11 @@ public final boolean login() throws LoginException {
if (CommonUtils.isBlank(service)) {
logger.info("Login failed because required CAS service parameter not provided.");
throw new LoginException(
- "Neither login module nor callback handler provided required service parameter.");
+ "Neither login module nor callback handler provided required service parameter.");
}
try {
logger.debug("Attempting ticket validation with service={} and ticket={}", service,
- this.ticket);
+ this.ticket);
this.assertion = this.ticketValidator.validate(this.ticket.getName(), service);
} catch (final Exception e) {
@@ -343,42 +391,13 @@ public final boolean login() throws LoginException {
return result;
}
- @Override
- public final boolean abort() throws LoginException {
- if (this.ticket != null) {
- this.ticket = null;
- }
- if (this.assertion != null) {
- this.assertion = null;
- }
- return true;
- }
-
- /**
- * Operations to perform before doing commit.
- *
- * @return true if you'd like commit to continue, false otherwise.
- */
- protected boolean preCommit() {
- return true;
- }
-
- /**
- * This occurs after commit is processed.
- *
- * @param result the result from the login attempt.
- */
- protected void postCommit(final boolean result) {
- // template method
- }
-
@Override
public final boolean commit() throws LoginException {
if (!preCommit()) {
return false;
}
- boolean result = false;
+ var result = false;
try {
if (this.assertion != null) {
if (this.ticket != null) {
@@ -387,39 +406,10 @@ public final boolean commit() throws LoginException {
throw new LoginException("Ticket credential not found.");
}
- final AssertionPrincipal casPrincipal = new AssertionPrincipal(this.assertion.getPrincipal().getName(),
- this.assertion);
+ final Principal casPrincipal = new AssertionPrincipal(this.assertion.getPrincipal().getName(),
+ this.assertion);
this.subject.getPrincipals().add(casPrincipal);
- // Add group containing principal as sole member
- // Supports JBoss JAAS use case
- final Group principalGroup = new SimpleGroup(this.principalGroupName);
- principalGroup.addMember(casPrincipal);
- this.subject.getPrincipals().add(principalGroup);
-
- // Add group principal containing role data
- final Group roleGroup = new SimpleGroup(this.roleGroupName);
-
- for (final String defaultRole : defaultRoles) {
- roleGroup.addMember(new SimplePrincipal(defaultRole));
- }
-
- final Map attributes = this.assertion.getPrincipal().getAttributes();
- for (final String key : attributes.keySet()) {
- if (this.roleAttributeNames.contains(key)) {
- // Attribute value is Object if singular or Collection if plural
- final Object value = attributes.get(key);
- if (value instanceof Collection>) {
- for (final Object o : (Collection>) value) {
- roleGroup.addMember(new SimplePrincipal(o.toString()));
- }
- } else {
- roleGroup.addMember(new SimplePrincipal(value.toString()));
- }
- }
- }
- this.subject.getPrincipals().add(roleGroup);
-
// Place principal name in shared state for downstream JAAS modules (module chaining use case)
this.sharedState.put(LOGIN_NAME, assertion.getPrincipal().getName());
@@ -443,6 +433,17 @@ public final boolean commit() throws LoginException {
return result;
}
+ @Override
+ public final boolean abort() throws LoginException {
+ if (this.ticket != null) {
+ this.ticket = null;
+ }
+ if (this.assertion != null) {
+ this.assertion = null;
+ }
+ return true;
+ }
+
@Override
public final boolean logout() throws LoginException {
logger.debug("Performing logout.");
@@ -453,7 +454,7 @@ public final boolean logout() throws LoginException {
// Remove cache entry if assertion caching is enabled
if (this.cacheAssertions) {
- for (final TicketCredential ticket : this.subject.getPrivateCredentials(TicketCredential.class)) {
+ for (final var ticket : this.subject.getPrivateCredentials(TicketCredential.class)) {
logger.debug("Removing cached assertion for {}", ticket);
ASSERTION_CACHE.remove(ticket);
}
@@ -462,7 +463,6 @@ public final boolean logout() throws LoginException {
// Remove all CAS principals
removePrincipalsOfType(AssertionPrincipal.class);
removePrincipalsOfType(SimplePrincipal.class);
- removePrincipalsOfType(SimpleGroup.class);
// Remove all CAS credentials
removeCredentialsOfType(TicketCredential.class);
@@ -473,12 +473,48 @@ public final boolean logout() throws LoginException {
return true;
}
+ /**
+ * Operations to perform before doing login.
+ *
+ * @return true if you'd like login to continue, false otherwise.
+ */
+ protected static boolean preLogin() {
+ return true;
+ }
+
+ /**
+ * This occurs after logout is processed.
+ *
+ * @param result the result from the login attempt.
+ */
+ protected void postLogin(final boolean result) {
+ // template method
+ }
+
+ /**
+ * Operations to perform before doing commit.
+ *
+ * @return true if you'd like commit to continue, false otherwise.
+ */
+ protected static boolean preCommit() {
+ return true;
+ }
+
+ /**
+ * This occurs after commit is processed.
+ *
+ * @param result the result from the login attempt.
+ */
+ protected void postCommit(final boolean result) {
+ // template method
+ }
+
/**
* Happens before logout occurs.
*
* @return true if we should continue, false otherwise.
*/
- protected boolean preLogout() {
+ protected static boolean preLogout() {
return true;
}
@@ -491,26 +527,27 @@ protected void postLogout() {
/**
* Creates a {@link TicketValidator} instance from a class name and map of property name/value pairs.
- * @param className Fully-qualified name of {@link TicketValidator} concrete class.
+ *
+ * @param className Fully-qualified name of {@link TicketValidator} concrete class.
* @param propertyMap Map of property name/value pairs to set on validator instance.
* @return Ticket validator with properties set.
*/
private TicketValidator createTicketValidator(final String className, final Map propertyMap) {
CommonUtils.assertTrue(propertyMap.containsKey("casServerUrlPrefix"),
- "Required property casServerUrlPrefix not found.");
+ "Required property casServerUrlPrefix not found.");
final Class validatorClass = ReflectUtils.loadClass(className);
- final TicketValidator validator = ReflectUtils.newInstance(validatorClass,
- propertyMap.get("casServerUrlPrefix"));
+ final var validator = ReflectUtils.newInstance(validatorClass,
+ propertyMap.get("casServerUrlPrefix"));
try {
- final BeanInfo info = Introspector.getBeanInfo(validatorClass);
+ final var info = Introspector.getBeanInfo(validatorClass);
- for (final String property : propertyMap.keySet()) {
+ for (final var property : propertyMap.keySet()) {
if (!"casServerUrlPrefix".equals(property)) {
logger.debug("Attempting to set TicketValidator property {}", property);
- final String value = (String) propertyMap.get(property);
- final PropertyDescriptor pd = ReflectUtils.getPropertyDescriptor(info, property);
+ final var value = (String) propertyMap.get(property);
+ final var pd = ReflectUtils.getPropertyDescriptor(info, property);
if (pd != null) {
ReflectUtils.setProperty(property, convertIfNecessary(pd, value), validator, info);
logger.debug("Set {} = {}", property, value);
@@ -526,33 +563,9 @@ private TicketValidator createTicketValidator(final String className, final Map<
return validator;
}
- /**
- * Attempts to do simple type conversion from a string value to the type expected
- * by the given property.
- *
- * Currently only conversion to int, long, and boolean are supported.
- *
- * @param pd Property descriptor of target property to set.
- * @param value Property value as a string.
- * @return Value converted to type expected by property if a conversion strategy exists.
- */
- private static Object convertIfNecessary(final PropertyDescriptor pd, final String value) {
- if (String.class.equals(pd.getPropertyType())) {
- return value;
- } else if (boolean.class.equals(pd.getPropertyType())) {
- return Boolean.valueOf(value);
- } else if (int.class.equals(pd.getPropertyType())) {
- return new Integer(value);
- } else if (long.class.equals(pd.getPropertyType())) {
- return new Long(value);
- } else {
- throw new IllegalArgumentException("No conversion strategy exists for property " + pd.getName()
- + " of type " + pd.getPropertyType());
- }
- }
-
/**
* Removes all principals of the given type from the JAAS subject.
+ *
* @param clazz Type of principal to remove.
*/
private void removePrincipalsOfType(final Class extends Principal> clazz) {
@@ -561,6 +574,7 @@ private void removePrincipalsOfType(final Class extends Principal> clazz) {
/**
* Removes all credentials of the given type from the JAAS subject.
+ *
* @param clazz Type of principal to remove.
*/
private void removeCredentialsOfType(final Class extends Principal> clazz) {
@@ -572,12 +586,12 @@ private void removeCredentialsOfType(final Class extends Principal> clazz) {
*/
private void cleanCache() {
logger.debug("Cleaning assertion cache of size {}", ASSERTION_CACHE.size());
- final Iterator> iter = ASSERTION_CACHE.entrySet().iterator();
- final Calendar cutoff = Calendar.getInstance();
+ final var iter = ASSERTION_CACHE.entrySet().iterator();
+ final var cutoff = Calendar.getInstance();
cutoff.setTimeInMillis(System.currentTimeMillis() - this.cacheTimeoutUnit.toMillis(this.cacheTimeout));
while (iter.hasNext()) {
- final Assertion assertion = iter.next().getValue();
- final Calendar created = Calendar.getInstance();
+ final var assertion = iter.next().getValue();
+ final var created = Calendar.getInstance();
created.setTime(assertion.getValidFromDate());
if (created.before(cutoff)) {
logger.debug("Removing expired assertion for principal {}", assertion.getPrincipal());
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/jaas/ServiceAndTicketCallbackHandler.java b/cas-client-core/src/main/java/org/apereo/cas/client/jaas/ServiceAndTicketCallbackHandler.java
similarity index 83%
rename from cas-client-core/src/main/java/org/jasig/cas/client/jaas/ServiceAndTicketCallbackHandler.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/jaas/ServiceAndTicketCallbackHandler.java
index 2f5f52eaf..429364e68 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/jaas/ServiceAndTicketCallbackHandler.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/jaas/ServiceAndTicketCallbackHandler.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,10 +16,14 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.jaas;
+package org.apereo.cas.client.jaas;
+import javax.security.auth.callback.Callback;
+import javax.security.auth.callback.CallbackHandler;
+import javax.security.auth.callback.NameCallback;
+import javax.security.auth.callback.PasswordCallback;
+import javax.security.auth.callback.UnsupportedCallbackException;
import java.io.IOException;
-import javax.security.auth.callback.*;
/**
* Callback handler that provides the CAS service and ticket to a
@@ -52,7 +56,7 @@ public ServiceAndTicketCallbackHandler(final String service, final String ticket
@Override
public void handle(final Callback[] callbacks) throws IOException, UnsupportedCallbackException {
- for (final Callback callback : callbacks) {
+ for (final var callback : callbacks) {
if (callback instanceof NameCallback) {
((NameCallback) callback).setName(this.service);
} else if (callback instanceof PasswordCallback) {
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/jaas/Servlet3AuthenticationFilter.java b/cas-client-core/src/main/java/org/apereo/cas/client/jaas/Servlet3AuthenticationFilter.java
similarity index 74%
rename from cas-client-core/src/main/java/org/jasig/cas/client/jaas/Servlet3AuthenticationFilter.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/jaas/Servlet3AuthenticationFilter.java
index dc06a9353..b1a961fc5 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/jaas/Servlet3AuthenticationFilter.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/jaas/Servlet3AuthenticationFilter.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,22 +16,21 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.jaas;
+package org.apereo.cas.client.jaas;
-import java.io.IOException;
-import java.security.GeneralSecurityException;
+import org.apereo.cas.client.Protocol;
+import org.apereo.cas.client.util.AbstractCasFilter;
+import org.apereo.cas.client.util.WebUtils;
-import javax.servlet.FilterChain;
-import javax.servlet.ServletException;
-import javax.servlet.ServletRequest;
-import javax.servlet.ServletResponse;
-import javax.servlet.http.HttpServletRequest;
-import javax.servlet.http.HttpServletResponse;
-import javax.servlet.http.HttpSession;
+import jakarta.servlet.FilterChain;
+import jakarta.servlet.ServletException;
+import jakarta.servlet.ServletRequest;
+import jakarta.servlet.ServletResponse;
+import jakarta.servlet.http.HttpServletRequest;
+import jakarta.servlet.http.HttpServletResponse;
-import org.jasig.cas.client.Protocol;
-import org.jasig.cas.client.util.AbstractCasFilter;
-import org.jasig.cas.client.util.CommonUtils;
+import java.io.IOException;
+import java.security.GeneralSecurityException;
/**
* Servlet filter performs a programmatic JAAS login using the Servlet 3.0 HttpServletRequest#login() facility.
@@ -39,14 +38,14 @@
*
* The filter executes when it receives a CAS ticket and expects the
* {@link CasLoginModule} JAAS module to perform the CAS
- * ticket validation in order to produce an {@link org.jasig.cas.client.jaas.AssertionPrincipal} from which
+ * ticket validation in order to produce an {@link AssertionPrincipal} from which
* the CAS assertion is obtained and inserted into the session to enable SSO.
*
* If a service init-param is specified for this filter, it supersedes
* the service defined for the {@link CasLoginModule}.
*
- * @author Daniel Fisher
- * @author Marvin S. Addison
+ * @author Daniel Fisher
+ * @author Marvin S. Addison
* @since 3.3
*/
public final class Servlet3AuthenticationFilter extends AbstractCasFilter {
@@ -58,18 +57,18 @@ public Servlet3AuthenticationFilter() {
@Override
public void doFilter(final ServletRequest servletRequest, final ServletResponse servletResponse,
final FilterChain chain) throws IOException, ServletException {
- final HttpServletRequest request = (HttpServletRequest) servletRequest;
- final HttpServletResponse response = (HttpServletResponse) servletResponse;
- final HttpSession session = request.getSession();
- final String ticket = CommonUtils.safeGetParameter(request, getProtocol().getArtifactParameterName());
+ final var request = (HttpServletRequest) servletRequest;
+ final var response = (HttpServletResponse) servletResponse;
+ final var session = request.getSession();
+ final var ticket = WebUtils.safeGetParameter(request, getProtocol().getArtifactParameterName());
if (session != null && session.getAttribute(CONST_CAS_ASSERTION) == null && ticket != null) {
try {
- final String service = constructServiceUrl(request, response);
+ final var service = constructServiceUrl(request, response);
logger.debug("Attempting CAS ticket validation with service={} and ticket={}", service, ticket);
request.login(service, ticket);
if (request.getUserPrincipal() instanceof AssertionPrincipal) {
- final AssertionPrincipal principal = (AssertionPrincipal) request.getUserPrincipal();
+ final var principal = (AssertionPrincipal) request.getUserPrincipal();
logger.debug("Installing CAS assertion into session.");
request.getSession().setAttribute(CONST_CAS_ASSERTION, principal.getAssertion());
} else {
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/jaas/TicketCredential.java b/cas-client-core/src/main/java/org/apereo/cas/client/jaas/TicketCredential.java
similarity index 85%
rename from cas-client-core/src/main/java/org/jasig/cas/client/jaas/TicketCredential.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/jaas/TicketCredential.java
index 16814ee09..4d4039629 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/jaas/TicketCredential.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/jaas/TicketCredential.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,7 +16,7 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.jaas;
+package org.apereo.cas.client.jaas;
import java.security.Principal;
@@ -49,27 +49,30 @@ public String getName() {
return this.ticket;
}
- public String toString() {
- return this.ticket;
+ public int hashCode() {
+ var hash = HASHCODE_SEED;
+ hash = hash * 31 + (ticket == null ? 0 : ticket.hashCode());
+ return hash;
}
public boolean equals(final Object o) {
- if (this == o)
+ if (this == o) {
return true;
- if (o == null || getClass() != o.getClass())
+ }
+ if (o == null || getClass() != o.getClass()) {
return false;
+ }
- final TicketCredential that = (TicketCredential) o;
+ final var that = (TicketCredential) o;
- if (ticket != null ? !ticket.equals(that.ticket) : that.ticket != null)
+ if (ticket != null ? !ticket.equals(that.ticket) : that.ticket != null) {
return false;
+ }
return true;
}
- public int hashCode() {
- int hash = HASHCODE_SEED;
- hash = hash * 31 + (ticket == null ? 0 : ticket.hashCode());
- return hash;
+ public String toString() {
+ return this.ticket;
}
}
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/proxy/AbstractEncryptedProxyGrantingTicketStorageImpl.java b/cas-client-core/src/main/java/org/apereo/cas/client/proxy/AbstractEncryptedProxyGrantingTicketStorageImpl.java
similarity index 91%
rename from cas-client-core/src/main/java/org/jasig/cas/client/proxy/AbstractEncryptedProxyGrantingTicketStorageImpl.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/proxy/AbstractEncryptedProxyGrantingTicketStorageImpl.java
index 9cfa69727..0d6536dab 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/proxy/AbstractEncryptedProxyGrantingTicketStorageImpl.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/proxy/AbstractEncryptedProxyGrantingTicketStorageImpl.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,17 +16,17 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.proxy;
+package org.apereo.cas.client.proxy;
-import org.jasig.cas.client.configuration.ConfigurationKeys;
+import org.apereo.cas.client.configuration.ConfigurationKeys;
+import javax.crypto.Cipher;
+import javax.crypto.SecretKeyFactory;
+import javax.crypto.spec.DESedeKeySpec;
import java.security.InvalidKeyException;
import java.security.Key;
import java.security.NoSuchAlgorithmException;
import java.security.spec.InvalidKeySpecException;
-import javax.crypto.Cipher;
-import javax.crypto.SecretKeyFactory;
-import javax.crypto.spec.DESedeKeySpec;
/**
* Provides encryption capabilities. Not entirely safe to configure since we have no way of controlling the
@@ -43,7 +43,7 @@ public abstract class AbstractEncryptedProxyGrantingTicketStorageImpl implements
private String cipherAlgorithm = ConfigurationKeys.CIPHER_ALGORITHM.getDefaultValue();
public final void setSecretKey(final String key) throws NoSuchAlgorithmException, InvalidKeyException,
- InvalidKeySpecException {
+ InvalidKeySpecException {
this.key = SecretKeyFactory.getInstance(this.cipherAlgorithm).generateSecret(new DESedeKeySpec(key.getBytes()));
}
@@ -84,7 +84,7 @@ private String encrypt(final String value) {
}
try {
- final Cipher cipher = Cipher.getInstance(this.cipherAlgorithm);
+ final var cipher = Cipher.getInstance(this.cipherAlgorithm);
cipher.init(Cipher.ENCRYPT_MODE, this.key);
return new String(cipher.doFinal(value.getBytes()));
} catch (final Exception e) {
@@ -102,7 +102,7 @@ private String decrypt(final String value) {
}
try {
- final Cipher cipher = Cipher.getInstance(this.cipherAlgorithm);
+ final var cipher = Cipher.getInstance(this.cipherAlgorithm);
cipher.init(Cipher.DECRYPT_MODE, this.key);
return new String(cipher.doFinal(value.getBytes()));
} catch (final Exception e) {
diff --git a/cas-client-core/src/main/java/org/jasig/cas/client/proxy/Cas20ProxyRetriever.java b/cas-client-core/src/main/java/org/apereo/cas/client/proxy/Cas20ProxyRetriever.java
similarity index 83%
rename from cas-client-core/src/main/java/org/jasig/cas/client/proxy/Cas20ProxyRetriever.java
rename to cas-client-core/src/main/java/org/apereo/cas/client/proxy/Cas20ProxyRetriever.java
index 10d455149..6deec531a 100644
--- a/cas-client-core/src/main/java/org/jasig/cas/client/proxy/Cas20ProxyRetriever.java
+++ b/cas-client-core/src/main/java/org/apereo/cas/client/proxy/Cas20ProxyRetriever.java
@@ -6,9 +6,9 @@
* Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a
* copy of the License at the following location:
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
+ *
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
@@ -16,16 +16,19 @@
* specific language governing permissions and limitations
* under the License.
*/
-package org.jasig.cas.client.proxy;
+package org.apereo.cas.client.proxy;
+
+import org.apereo.cas.client.ssl.HttpURLConnectionFactory;
+import org.apereo.cas.client.util.CommonUtils;
+import org.apereo.cas.client.util.XmlUtils;
-import java.net.URL;
-import java.net.URLEncoder;
-import org.jasig.cas.client.ssl.HttpURLConnectionFactory;
-import org.jasig.cas.client.util.CommonUtils;
-import org.jasig.cas.client.util.XmlUtils;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
+import java.io.Serial;
+import java.net.URL;
+import java.net.URLEncoder;
+
/**
* Implementation of a ProxyRetriever that follows the CAS 2.0 specification.
* For more information on the CAS 2.0 specification, please see the
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *