You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CAS 5.2.X文档中“返回的断言长度”术语含义咨询

Understanding "Assertion Length" in CAS 5.2.X JWT Service Tickets

Hey there, let's demystify that confusing "assertion length" phrase from the CAS 5.2.X docs when using JWT as service tickets.

First, let's ground this in how CAS handles authentication:
When a user successfully logs in, CAS generates an Assertion object—this is essentially a container holding the user's authenticated identity, attributes, and crucially, a validity window for that authentication result. The "assertion length" the docs refer to is simply the validity period (duration) assigned to this Assertion object.

Breakdown of how this controls JWT expiration:

  • When you specify an assertion validity period: CAS will take that duration and set the JWT's exp (expiration) claim to current time + assertion validity period. This makes the JWT's lifespan directly tied to how long you've configured the authentication assertion to be valid.
    • You can set this either via CAS configuration properties, or in custom authentication logic (like a custom AuthenticationHandler where you explicitly define the assertion's start and end times).
    • Example config in cas.properties:
      # Set assertion validity to 30 minutes (1800 seconds)
      cas.authn.assertion.validity=1800
      
    • Example custom code snippet (simplified):
      @Override
      protected HandlerResult authenticateInternal(Credential credential) {
          // Your authentication logic here...
          // Create assertion with 30-minute validity
          Date expiration = new Date(System.currentTimeMillis() + 1800000);
          Assertion assertion = new DefaultAssertion(authenticatedPrincipal, new Date(), expiration);
          return new HandlerResult(this, credential, assertion);
      }
      
  • When no assertion validity is specified: CAS falls back to using the global SSO session timeout (configured via properties like ticket.tgt.timeout). In this case, the JWT's expiration will match when the user's overall SSO session is set to expire.

To put it plainly: "Assertion length" is just the amount of time the authentication result (the Assertion) is considered valid, and CAS uses that duration to set the JWT's expiration date. If you don't define that, it defaults to how long the user's SSO session lasts.

内容的提问来源于stack exchange,提问作者Newbee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 08:37:31