Apereo CAS 5.2.0如何关闭属性缓存?实现OAuth2.0端点实时查询
Absolutely, you can disable the caching mechanism so CAS retrieves fresh user attributes from your JDBC repository every time the /oauth2.0/profile endpoint is accessed. Here's what you need to configure step by step:
1. Disable Caching for the JDBC Attribute Repository
First, turn off caching specifically for your JDBC attribute repository. Add these settings to your CAS properties file:
# Disable caching for the JDBC attribute repository directly cas.authn.attributeRepository.jdbc[0].cache.enabled=false # Optional fallback for older CAS versions where the above might not apply cas.authn.attributeRepository.jdbc[0].cache.expiration=0 cas.authn.attributeRepository.jdbc[0].cache.maxSize=0
This ensures CAS skips any cached attribute values and pulls directly from your database whenever attributes are requested.
2. Disable Caching for the OAuth2 Profile Endpoint
Next, ensure the /oauth2.0/profile endpoint doesn't rely on the SSO session's cached attributes. Add this configuration:
# Force the OAuth2 profile endpoint to fetch fresh attributes on each request cas.oauth.profile.cache.enabled=false
This setting overrides the default behavior of reusing session-cached data, triggering a fresh lookup from your JDBC repository every time the endpoint is hit.
Quick Note for Version Compatibility
Keep in mind that property names might shift slightly between CAS versions (like 6.x vs 7.x). If you run into unexpected behavior, cross-check your specific CAS version's documentation to confirm the exact property keys.
内容的提问来源于stack exchange,提问作者Stefan

