Apereo CAS 6.3.3两类随机异常问题求助:非法execution参数触发500错误与过期服务票据导致重定向过多
Great questions—let's break down solutions for both issues in your Apereo CAS 6.3.3 overlay:
execution Parameters When users hit the CAS login page with a malformed execution value (like ?execution=anything), you can override the default 500 error behavior to redirect straight to a clean login page. Here's how:
- Create a custom exception handler using Spring's
@ControllerAdviceto catchBadlyFormattedFlowExecutionKeyException:import org.springframework.web.bind.annotation.ControllerAdvice; import org.springframework.web.bind.annotation.ExceptionHandler; import org.springframework.web.servlet.ModelAndView; import org.springframework.webflow.execution.repository.BadlyFormattedFlowExecutionKeyException; @ControllerAdvice public class CasCustomExceptionHandler { @ExceptionHandler(BadlyFormattedFlowExecutionKeyException.class) public ModelAndView handleInvalidFlowExecutionKey() { // Redirect to the base CAS login page without the bad execution parameter return new ModelAndView("redirect:/cas/login"); } } - Register the handler in your CAS overlay's Spring config (e.g., add it as a
@Beanin a custom configuration class likesrc/main/java/com/yourorg/cas/config/CustomCasConfig.java).
After deploying this change, testing https://your-cas-server/cas/login?execution=anything should land users on the normal login page instead of seeing a 500 error.
Expired service tickets can trigger a loop between your application and CAS because CAS tries to notify the app of the expired ticket, which then redirects back to CAS. To fix this, configure CAS to redirect users directly to the login page instead of starting the loop:
- Use CAS properties first (simplest approach) in your
application.propertiesorapplication.yml:# Force redirect to login when service tickets are invalid/expired cas.ticket.service.error.redirect-to-login=true # Optional: Customize the session expired message (won't be shown if redirect is enabled) cas.ticket.service.error.message=Your session has expired. Please log in again. - If properties aren't sufficient, create a custom exception handler for ticket validation:
import org.apereo.cas.ticket.ExpiredTicketException; import org.apereo.cas.web.flow.ServiceValidationExceptionHandler; import org.springframework.web.servlet.ModelAndView; public class CustomServiceValidationHandler extends ServiceValidationExceptionHandler { @Override public ModelAndView handleException(Exception e) { if (e instanceof ExpiredTicketException) { // Break the loop by redirecting directly to CAS login return new ModelAndView("redirect:/cas/login"); } // Fall back to default handling for other ticket errors return super.handleException(e); } } - Register the custom handler in your Spring config to replace the default bean:
@Bean public ServiceValidationExceptionHandler serviceValidationExceptionHandler() { return new CustomServiceValidationHandler(); }
This will ensure that when an expired service ticket is detected, users are sent straight to the CAS login page instead of getting stuck in a redirect loop.
内容的提问来源于stack exchange,提问作者DLB555

