Configure Service Access Strategy

The access strategy of a registered service provides fine-grained control over the service authorization rules. It describes whether the service is allowed to use the CAS server, allowed to participate in single sign-on authentication, etc. Additionally, it may be configured to require a certain set of principal attributes that must exist before access can be granted to the service. This behavior allows one to configure various attributes in terms of access roles for the application and define rules that would be enacted and validated when an authentication request from the application arrives.

Strategy Resource
Basic See this guide.
Unauthorized URLs See this guide.
ABAC See this guide.
Groovy See this guide.
Time-Based See this guide.
(Remote) HTTP Request See this guide.
Grouper See this guide.
AWS Verified Permissions See this guide.
OpenFGA See this guide.
Permify See this guide.
Cerbos See this guide.
Open Policy Agent See this guide.
Chaining See this guide.
Custom See this guide.
SCIM See this guide.

Actuator Endpoints

The following endpoints are provided by CAS:

serviceAccess
CAS endpoint1 operationNot exposed by defaultcas-server-support-reports
1

Include the module that provides this endpoint in the WAR overlay:

1
2
3
4
5
<dependency>
    <groupId>org.apereo.cas</groupId>
    <artifactId>cas-server-support-reports</artifactId>
    <version>${cas.version}</version>
</dependency>
1
implementation "org.apereo.cas:cas-server-support-reports:${project.'cas.version'}"
1
2
3
4
5
6
7
8
9
dependencyManagement {
    imports {
        mavenBom "org.apereo.cas:cas-server-support-bom:${project.'cas.version'}"
    }
}

dependencies {
    implementation "org.apereo.cas:cas-server-support-reports"
}
1
2
3
4
5
6
7
8
9
10
dependencies {
    /*
        The following platform references are included automatically and are listed for reference only.

        implementation enforcedPlatform("org.apereo.cas:cas-server-support-bom:${project.'cas.version'}")
        implementation platform(org.springframework.boot.gradle.plugin.SpringBootPlugin.BOM_COORDINATES)
        
    */
    implementation "org.apereo.cas:cas-server-support-reports"
}
2

Turn the endpoint on and expose it over the web. One entry covers every operation. By default only info, health and status are exposed.

1
2
management.endpoint.serviceAccess.access=UNRESTRICTED
management.endpoints.web.exposure.include=serviceAccess

Endpoints may be mapped to other paths. For example, to serve health at healthcheck:

1
management.endpoints.web.path-mapping.health=healthcheck