You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@shiro.apache.org by "Jérôme Leleu (JIRA)" <ji...@apache.org> on 2012/07/01 14:45:54 UTC

[jira] [Commented] (SHIRO-373) Complete CAS remember-me support

    [ https://issues.apache.org/jira/browse/SHIRO-373?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13404720#comment-13404720 ] 

Jérôme Leleu commented on SHIRO-373:
------------------------------------

I started a discussion on Shiro dev mailing list here : http://shiro-developer.582600.n2.nabble.com/Complete-CAS-remember-me-support-td7577498.html.

                
> Complete CAS remember-me support
> --------------------------------
>
>                 Key: SHIRO-373
>                 URL: https://issues.apache.org/jira/browse/SHIRO-373
>             Project: Shiro
>          Issue Type: Bug
>            Reporter: Jérôme Leleu
>         Attachments: svn-CasAuthenticatedUserFilter.patch
>
>
> I was preparing a demo on CAS support for Shiro : https://github.com/leleuj/cas-shiro-demo and I did realize the remember-me feature is not fully addressed.
> One use case is missing : if the user is already remembered (by CAS) and want to be authenticated, it should be redirected to CAS server with a specific parameter (renew=true) to force CAS re-authentication.
> For this use case, I created a CasAuthenticatedUserFilter which checks if the user is authenticated (not remembered) and sends him to the CAS server if he's not (with the specific parameter to force re-authentication if he's already remembered).

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira