CAS 5.2.X文档中“返回的断言长度”术语含义咨询
Hey there, let's demystify that confusing "assertion length" phrase from the CAS 5.2.X docs when using JWT as service tickets.
First, let's ground this in how CAS handles authentication:
When a user successfully logs in, CAS generates an Assertion object—this is essentially a container holding the user's authenticated identity, attributes, and crucially, a validity window for that authentication result. The "assertion length" the docs refer to is simply the validity period (duration) assigned to this Assertion object.
Breakdown of how this controls JWT expiration:
- When you specify an assertion validity period: CAS will take that duration and set the JWT's
exp(expiration) claim tocurrent time + assertion validity period. This makes the JWT's lifespan directly tied to how long you've configured the authentication assertion to be valid.- You can set this either via CAS configuration properties, or in custom authentication logic (like a custom
AuthenticationHandlerwhere you explicitly define the assertion's start and end times). - Example config in
cas.properties:# Set assertion validity to 30 minutes (1800 seconds) cas.authn.assertion.validity=1800 - Example custom code snippet (simplified):
@Override protected HandlerResult authenticateInternal(Credential credential) { // Your authentication logic here... // Create assertion with 30-minute validity Date expiration = new Date(System.currentTimeMillis() + 1800000); Assertion assertion = new DefaultAssertion(authenticatedPrincipal, new Date(), expiration); return new HandlerResult(this, credential, assertion); }
- You can set this either via CAS configuration properties, or in custom authentication logic (like a custom
- When no assertion validity is specified: CAS falls back to using the global SSO session timeout (configured via properties like
ticket.tgt.timeout). In this case, the JWT's expiration will match when the user's overall SSO session is set to expire.
To put it plainly: "Assertion length" is just the amount of time the authentication result (the Assertion) is considered valid, and CAS uses that duration to set the JWT's expiration date. If you don't define that, it defaults to how long the user's SSO session lasts.
内容的提问来源于stack exchange,提问作者Newbee

