CAS 6, AbstractNonInteractiveCredentialsAction on Trusted AuthN with incoming SAML Assertion

8 views
Skip to first unread message

Yan Zhou

unread,
Sep 19, 2023, 3:53:01 PM9/19/23
to CAS Community
hello,

for historical reasons, our CAS set-up needs to support accepting an incoming SAML Assertion (validate, etc.) from HTTP request parameter, perform authentication as  the user principal in the incoming SAML assertion, basically, we trust the SAML authN done by our vendor earlier, and create CAS session so that user can SSO into our apps.

We have overridden AbstractNonInteractiveCredentialsAction  to constructCredentialsFromRequest(), i.e., we create a user-defined Credential object and then authenticate, create SSO, by overriding AbstractAuthenticationHandler.

that has worked well, but I do not see any documentation on this in CAS 6.6.x document, the class is still there in 6.6.x, is there now a better and easier way to implement Trusted Authentication based on SAML (XML) input from HTTP request parameter?

Thx!

Ray Bon

unread,
Sep 25, 2023, 3:51:51 PM9/25/23
to cas-...@apereo.org
Yan,


Ray

On Tue, 2023-09-19 at 12:28 -0700, Yan Zhou wrote:
Notice: This message was sent from outside the University of Victoria email system. Please be cautious with links and sensitive information.
Reply all
Reply to author
Forward
0 new messages