You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在CAS Server 5.2.x版本登录后设置额外会话Cookie?

Setting a Shared Session Cookie Post-CAS 5.2.x Login

Great question! In CAS 5.2.x, there are a couple of reliable ways to set an additional, non-security-focused session cookie that’s shared across all your CAS clients (since they share the same domain). Let me break down the two most common approaches:

Approach 1: Use an Authentication Success Event Listener

CAS fires an AuthenticationSuccessEvent when a user successfully logs in. You can create a custom listener to catch this event and attach your shared cookie to the response.

Step 1: Create the Listener Class

Implement ApplicationListener<AuthenticationSuccessEvent> to handle the login success event and set the cookie:

import org.apereo.cas.authentication.AuthenticationSuccessEvent;
import org.springframework.context.ApplicationListener;
import org.springframework.stereotype.Component;
import javax.servlet.http.Cookie;
import javax.servlet.http.HttpServletResponse;
import org.springframework.web.context.request.RequestContextHolder;
import org.springframework.web.context.request.ServletRequestAttributes;

@Component
public class PostLoginSharedCookieListener implements ApplicationListener<AuthenticationSuccessEvent> {

    @Override
    public void onApplicationEvent(AuthenticationSuccessEvent event) {
        // Grab the current HTTP response from the request context
        ServletRequestAttributes attributes = (ServletRequestAttributes) RequestContextHolder.getRequestAttributes();
        if (attributes != null && attributes.getResponse() != null) {
            HttpServletResponse response = attributes.getResponse();
            
            // Configure your shared cookie
            Cookie sharedClientCookie = new Cookie("shared_client_cookie", "your_custom_value");
            // Set the root domain so all subdomain clients can access it
            sharedClientCookie.setDomain(".yourdomain.com");
            // Set path to root to cover all application paths
            sharedClientCookie.setPath("/");
            // Use -1 for a session cookie (expires when browser closes)
            sharedClientCookie.setMaxAge(-1);
            // Set to false if you need JS access; true if only server-side access is needed
            sharedClientCookie.setHttpOnly(false);
            // Enable secure flag if using HTTPS (strongly recommended for production)
            sharedClientCookie.setSecure(true);
            
            // Add the cookie to the response
            response.addCookie(sharedClientCookie);
        }
    }
}

Step 2: Deploy the Listener

Package this class into your CAS overlay project (the standard way to customize CAS) and ensure it’s picked up by Spring component scanning.

Approach 2: Add a Custom Action to the CAS Webflow

CAS uses Spring Webflow for its login workflow. You can insert a custom action right after authentication success to set the cookie.

Step 1: Create the Webflow Action Class

Extend AbstractAction to implement the cookie-setting logic:

import org.apereo.cas.web.support.WebUtils;
import org.springframework.webflow.action.AbstractAction;
import org.springframework.webflow.execution.Event;
import org.springframework.webflow.execution.RequestContext;
import javax.servlet.http.Cookie;
import javax.servlet.http.HttpServletResponse;

public class SetSharedCookieAction extends AbstractAction {

    @Override
    protected Event doExecute(RequestContext requestContext) {
        // Get the HTTP response from the webflow context
        HttpServletResponse response = WebUtils.getHttpServletResponse(requestContext);
        
        // Configure your shared cookie (same settings as approach 1)
        Cookie sharedClientCookie = new Cookie("shared_client_cookie", "your_custom_value");
        sharedClientCookie.setDomain(".yourdomain.com");
        sharedClientCookie.setPath("/");
        sharedClientCookie.setMaxAge(-1);
        sharedClientCookie.setHttpOnly(false);
        sharedClientCookie.setSecure(true);
        
        response.addCookie(sharedClientCookie);
        
        // Return a success event to continue the webflow
        return success();
    }
}

Step 2: Register the Action Bean

Add this bean definition to your CAS Spring configuration (e.g., cas-servlet.xml or a custom config file):

<bean id="setSharedCookieAction" class="com.yourorg.cas.actions.SetSharedCookieAction" />

Step 3: Update the Webflow Configuration

Modify the CAS login webflow (typically login-webflow.xml) to insert your action right after the authentication success step:

<action-state id="authenticationSuccess">
    <evaluate expression="authenticationSuccessAction" />
    <!-- Insert your custom cookie-setting action here -->
    <evaluate expression="setSharedCookieAction" />
    <transition on="success" to="sendTicketGrantingTicket" />
</action-state>

Key Notes for Both Approaches

  • Domain Configuration: Ensure the cookie’s domain is set to your root domain (e.g., .yourdomain.com) so all subdomain clients can access it. The leading dot ensures compatibility with older browsers.
  • Dynamic Values: To set a dynamic cookie value (like a user attribute), retrieve the user’s authentication details:
    • In the listener: event.getAuthentication().getAttributes().get("userAttributeKey")
    • In the webflow action: WebUtils.getAuthentication(requestContext).getAttributes().get("userAttributeKey")
  • Security: Always set secure=true if your CAS and clients use HTTPS to prevent the cookie from being transmitted over unencrypted connections.
  • Session vs Persistent: Use maxAge=-1 for a session cookie (expires on browser close) or a positive number (in seconds) for a persistent cookie.

内容的提问来源于stack exchange,提问作者Marinos An

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:27:04