如何在CAS Server 5.2.x版本登录后设置额外会话Cookie?
Great question! In CAS 5.2.x, there are a couple of reliable ways to set an additional, non-security-focused session cookie that’s shared across all your CAS clients (since they share the same domain). Let me break down the two most common approaches:
Approach 1: Use an Authentication Success Event Listener
CAS fires an AuthenticationSuccessEvent when a user successfully logs in. You can create a custom listener to catch this event and attach your shared cookie to the response.
Step 1: Create the Listener Class
Implement ApplicationListener<AuthenticationSuccessEvent> to handle the login success event and set the cookie:
import org.apereo.cas.authentication.AuthenticationSuccessEvent; import org.springframework.context.ApplicationListener; import org.springframework.stereotype.Component; import javax.servlet.http.Cookie; import javax.servlet.http.HttpServletResponse; import org.springframework.web.context.request.RequestContextHolder; import org.springframework.web.context.request.ServletRequestAttributes; @Component public class PostLoginSharedCookieListener implements ApplicationListener<AuthenticationSuccessEvent> { @Override public void onApplicationEvent(AuthenticationSuccessEvent event) { // Grab the current HTTP response from the request context ServletRequestAttributes attributes = (ServletRequestAttributes) RequestContextHolder.getRequestAttributes(); if (attributes != null && attributes.getResponse() != null) { HttpServletResponse response = attributes.getResponse(); // Configure your shared cookie Cookie sharedClientCookie = new Cookie("shared_client_cookie", "your_custom_value"); // Set the root domain so all subdomain clients can access it sharedClientCookie.setDomain(".yourdomain.com"); // Set path to root to cover all application paths sharedClientCookie.setPath("/"); // Use -1 for a session cookie (expires when browser closes) sharedClientCookie.setMaxAge(-1); // Set to false if you need JS access; true if only server-side access is needed sharedClientCookie.setHttpOnly(false); // Enable secure flag if using HTTPS (strongly recommended for production) sharedClientCookie.setSecure(true); // Add the cookie to the response response.addCookie(sharedClientCookie); } } }
Step 2: Deploy the Listener
Package this class into your CAS overlay project (the standard way to customize CAS) and ensure it’s picked up by Spring component scanning.
Approach 2: Add a Custom Action to the CAS Webflow
CAS uses Spring Webflow for its login workflow. You can insert a custom action right after authentication success to set the cookie.
Step 1: Create the Webflow Action Class
Extend AbstractAction to implement the cookie-setting logic:
import org.apereo.cas.web.support.WebUtils; import org.springframework.webflow.action.AbstractAction; import org.springframework.webflow.execution.Event; import org.springframework.webflow.execution.RequestContext; import javax.servlet.http.Cookie; import javax.servlet.http.HttpServletResponse; public class SetSharedCookieAction extends AbstractAction { @Override protected Event doExecute(RequestContext requestContext) { // Get the HTTP response from the webflow context HttpServletResponse response = WebUtils.getHttpServletResponse(requestContext); // Configure your shared cookie (same settings as approach 1) Cookie sharedClientCookie = new Cookie("shared_client_cookie", "your_custom_value"); sharedClientCookie.setDomain(".yourdomain.com"); sharedClientCookie.setPath("/"); sharedClientCookie.setMaxAge(-1); sharedClientCookie.setHttpOnly(false); sharedClientCookie.setSecure(true); response.addCookie(sharedClientCookie); // Return a success event to continue the webflow return success(); } }
Step 2: Register the Action Bean
Add this bean definition to your CAS Spring configuration (e.g., cas-servlet.xml or a custom config file):
<bean id="setSharedCookieAction" class="com.yourorg.cas.actions.SetSharedCookieAction" />
Step 3: Update the Webflow Configuration
Modify the CAS login webflow (typically login-webflow.xml) to insert your action right after the authentication success step:
<action-state id="authenticationSuccess"> <evaluate expression="authenticationSuccessAction" /> <!-- Insert your custom cookie-setting action here --> <evaluate expression="setSharedCookieAction" /> <transition on="success" to="sendTicketGrantingTicket" /> </action-state>
Key Notes for Both Approaches
- Domain Configuration: Ensure the cookie’s domain is set to your root domain (e.g.,
.yourdomain.com) so all subdomain clients can access it. The leading dot ensures compatibility with older browsers. - Dynamic Values: To set a dynamic cookie value (like a user attribute), retrieve the user’s authentication details:
- In the listener:
event.getAuthentication().getAttributes().get("userAttributeKey") - In the webflow action:
WebUtils.getAuthentication(requestContext).getAttributes().get("userAttributeKey")
- In the listener:
- Security: Always set
secure=trueif your CAS and clients use HTTPS to prevent the cookie from being transmitted over unencrypted connections. - Session vs Persistent: Use
maxAge=-1for a session cookie (expires on browser close) or a positive number (in seconds) for a persistent cookie.
内容的提问来源于stack exchange,提问作者Marinos An

