pac4j Google2Client auth delegation: How to unauthorize a profile?

Skip to first unread message

Oscar del Pozo

Jan 23, 2018, 10:10:34 AM1/23/18
to CAS Community

I'm migrating from CAS 4.0.5 to 5.2.1 and everything has gone perfect but I'm facing a problem with the Google OAuth authentication.

I have configured a delegate authentication to Google with pac4j successfully but I need to make a modification, only allow the emails which end with (I do agree that this kind of things should not be done at CAS because this is about authorization and not authentication, but I have to)

I have added a new AuthorizationGenerator to the Google2Client instance so, after the retrieve the user profile with the Google2ProfileDefinition class, I make my validation and in case that the user email is not a valid one, I set the profile identifier no blank. The blank identifier causes a FailedLoginException at AbstractPac4jAuthenticationHandler.

Everything seems to work fine but finally, I get the following exception and the CAS error page is shown.
2018-01-23 15:58:48,581 DEBUG [org.pac4j.oauth.profile.creator.OAuth20ProfileCreator] - <add access_token: ya29.Glx....... to profile>
2018-01-23 15:58:48,581 DEBUG [org.pac4j.oauth.profile.google2.Google2Profile] - <adding => key: access_token / value:XXX-XXX / class java.lang.String>
2018-01-23 15:58:48,581 DEBUG [org.pac4j.oauth.client.Google2Client] - <profile: #Google2Profile# | id: 112368488543222222114 | attributes: {name.familyName=del Pozo, emails=[org.pac4j.oauth.profile.google2.Google2Email@64f6a901], access_token=..., gender=MALE, displayName=Oscar del Pozo, name.givenName=Oscar, ... |>
2018-01-23 15:58:49,599 WARN [] - <Invalid user email>
2018-01-23 15:58:49,599 DEBUG [org.pac4j.oauth.profile.google2.Google2Profile] - <identifier: >
2018-01-23 15:58:51,789 ERROR [org.apereo.cas.authentication.PolicyBasedAuthenticationManager] - <Authentication has failed. Credentials may be incorrect or CAS cannot find authentication handler that supports [org.apereo.cas.authentication.principal.ClientCredential@2f8fc6b0[id=<null>]] of type [ClientCredential].>
2018-01-23 15:58:53,216 INFO [] - <Audit trail record BEGIN
WHO: null
WHAT: Supplied credentials: [org.apereo.cas.authentication.principal.ClientCredential@2f8fc6b0[id=<null>]]
ACTION: AUTHENTICATION_SUCCESS   (This is a reported bug, the authentication has actually failed:
WHEN: Tue Jan 23 15:58:53 CET 2018
2018-01-23 15:58:53,247 ERROR [] - <Forwarding to error page from request [/login] due to exception [Exception thrown executing in state 'clientAction' of flow 'login' -- action execution attributes were 'map[[empty]]']>
        at org.springframework.webflow.execution.ActionExecutor.execute( ~[spring-webflow-2.4.6.RELEASE.jar:2.4.6.RELEASE]
        at org.springframework.webflow.action.EvaluateAction.doExecute( ~[spring-webflow-2.4.6.RELEASE.jar:2.4.6.RELEASE]
        at org.springframework.webflow.action.AbstractAction.execute( ~[spring-webflow-2.4.6.RELEASE.jar:2.4.6.RELEASE] 
Caused by: org.apereo.cas.authentication.AuthenticationException: 1 errors, 0 successes
at org.apereo.cas.authentication.PolicyBasedAuthenticationManager.evaluateFinalAuthentication( ~[cas-server-core-authentication-5.2.1.jar:5.2.1]
at org.apereo.cas.authentication.PolicyBasedAuthenticationManager.authenticateInternal( ~[cas-server-core-authentication-5.2.1.jar:5.2.1]
at org.apereo.cas.authentication.PolicyBasedAuthenticationManager.authenticate( ~[cas-server-core-authentication-5.2.1.jar:5.2.1]

Is my approach correct?. Is it possible to do not show this CAS error and go to the 403 view?

Martin Bohun

Jan 23, 2018, 9:43:27 PM1/23/18
to CAS Community
Hello Oscar,

This is an example of one possible solution:
Our cas project (based on cas-4.0.x), uses Delegated Authentication (Facebook/Google/Twitter) to perform "one click" SignUp/SignIn.
We use a custom auth handler that uses the attributes (email, first_name, surname) returned by Facebook/Google/Twitter to either:
a) SignIn user if user with that email exist in the system already, OR
b) SignUp create the user in our system, and proceed to SignIn

So at that point in the code where we are receiving/processing the email address returned by Facebook/Google/Twitter:

one could do the type of filtering you want:
a) hardcode it there
b) externalize the email validation/check regexp into some properties/config file so 
c) fast/phugly/hack do the filtering in your LDAP, SQL query,



Oscar del Pozo

Jan 24, 2018, 6:08:15 AM1/24/18
to CAS Community
Hi Martin,

Thanks for your response. Sadly, I think that the result of implementing a custom Authentication Handler would be the same that I have now, a redirection to CAS error page since with my current implementation I'm throwing a FailedLoginException that it is exactly the same that you're doing.

So, I think that my question is not the correct one. I guess what I need is to modify the login-webflow to define what to do when an authentication failure happens. I'll follow the guide to try to do it.



Jan 25, 2018, 4:57:30 AM1/25/18
to CAS Community
The error  'map[[empty]]'] comes from the fact that the webflow from pac4j doesn't catch correctly the error sent by 'AbstractPac4jAuthenticationHandler'. 

From my point of view the solution would be to modify the webflow in order to "accept" your exception and to redirect to a new action you have defined.

2 solutions, you can override org.apereo.cas.web.flow.Pac4jWebflowConfigurer (faster) or extend the webflow via a new own configuration (nicer).
Modify the webflow by adding a new TransitionExecutingFlowExecutionExceptionHandler or adding a new TransitionSet catching the error into clientAction.

See some example from org.apereo.cas.web.flow.configurer.DefaultWebflowConfigurer

See as well that shows how the webflow can be modify in the case of pac4j

Oscar del Pozo

Jan 25, 2018, 5:21:18 AM1/25/18
to CAS Community
Hi Francis,

Modify the webflow by adding a new TransitionExecutingFlowExecutionExceptionHandler or adding a new TransitionSet catching the error into clientAction.

That's exactly what I have done right now and it's working. Thanks for your answer! 
Reply all
Reply to author
0 new messages