You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apereo CAS 6.3.3两类随机异常问题求助:非法execution参数触发500错误与过期服务票据导致重定向过多

Great questions—let's break down solutions for both issues in your Apereo CAS 6.3.3 overlay:

1. Redirect Instead of Throwing 500 for Invalid execution Parameters

When users hit the CAS login page with a malformed execution value (like ?execution=anything), you can override the default 500 error behavior to redirect straight to a clean login page. Here's how:

  • Create a custom exception handler using Spring's @ControllerAdvice to catch BadlyFormattedFlowExecutionKeyException:
    import org.springframework.web.bind.annotation.ControllerAdvice;
    import org.springframework.web.bind.annotation.ExceptionHandler;
    import org.springframework.web.servlet.ModelAndView;
    import org.springframework.webflow.execution.repository.BadlyFormattedFlowExecutionKeyException;
    
    @ControllerAdvice
    public class CasCustomExceptionHandler {
    
        @ExceptionHandler(BadlyFormattedFlowExecutionKeyException.class)
        public ModelAndView handleInvalidFlowExecutionKey() {
            // Redirect to the base CAS login page without the bad execution parameter
            return new ModelAndView("redirect:/cas/login");
        }
    }
    
  • Register the handler in your CAS overlay's Spring config (e.g., add it as a @Bean in a custom configuration class like src/main/java/com/yourorg/cas/config/CustomCasConfig.java).

After deploying this change, testing https://your-cas-server/cas/login?execution=anything should land users on the normal login page instead of seeing a 500 error.

2. Stop Redirect Loops from Expired Service Tickets

Expired service tickets can trigger a loop between your application and CAS because CAS tries to notify the app of the expired ticket, which then redirects back to CAS. To fix this, configure CAS to redirect users directly to the login page instead of starting the loop:

  • Use CAS properties first (simplest approach) in your application.properties or application.yml:
    # Force redirect to login when service tickets are invalid/expired
    cas.ticket.service.error.redirect-to-login=true
    # Optional: Customize the session expired message (won't be shown if redirect is enabled)
    cas.ticket.service.error.message=Your session has expired. Please log in again.
    
  • If properties aren't sufficient, create a custom exception handler for ticket validation:
    import org.apereo.cas.ticket.ExpiredTicketException;
    import org.apereo.cas.web.flow.ServiceValidationExceptionHandler;
    import org.springframework.web.servlet.ModelAndView;
    
    public class CustomServiceValidationHandler extends ServiceValidationExceptionHandler {
    
        @Override
        public ModelAndView handleException(Exception e) {
            if (e instanceof ExpiredTicketException) {
                // Break the loop by redirecting directly to CAS login
                return new ModelAndView("redirect:/cas/login");
            }
            // Fall back to default handling for other ticket errors
            return super.handleException(e);
        }
    }
    
  • Register the custom handler in your Spring config to replace the default bean:
    @Bean
    public ServiceValidationExceptionHandler serviceValidationExceptionHandler() {
        return new CustomServiceValidationHandler();
    }
    

This will ensure that when an expired service ticket is detected, users are sent straight to the CAS login page instead of getting stuck in a redirect loop.


内容的提问来源于stack exchange,提问作者DLB555

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 12:47:36