CAS 提供方在 Users & Permissions 中的设置
页面摘要: CAS 是一个 SSO 服务器,在支持 OIDC 的情况下部署时,Strapi 可将其用于身份验证。配置一个 CAS 服务定义,并在 Strapi 的 Users & Permissions 设置中提供客户端 ID、密钥和提供方子域名。
本页介绍如何为 Users & Permissions 功能 设置 CAS 提供方。
WARNING
CAS 配置
NOTE
远程 CAS 服务器可以配置为接受 localhost URL,你也可以运行一个接受这些 URL 的本地 CAS 服务器。
无需使用 ngrok。
- CAS 是一个 SSO 服务器,支持多种不同的方法来验证用户身份、 检索用户属性,并通过 SAML、OIDC 和 CAS 协议等协议将这些信息传递给应用程序。如果 CAS 部署时支持 OIDC,Strapi 可以使用 CAS 服务器进行身份验证。
- 你的公司或组织可能已经在使用 CAS,或者你可以通过克隆 CAS Overlay 项目,或使用较新的 CAS Initializr 来创建一个 overlay 项目,从而搭建一个本地 CAS 服务器。
- CAS 服务器必须进行配置,以便能够充当 OpenID Connect Provider(OpenID Connect 提供者)。
- 已知 CAS 6.3.x 及更高版本可与 Strapi 配合使用,但支持 OIDC 的旧版本也可能可用。
- 为 Strapi 定义一个 CAS OIDC 服务,并将其存储在所使用的任意 CAS 服务注册表中。
- 对于本地 Strapi 部署,CAS 服务定义可能如下所示:
{
"@class": "org.apereo.cas.services.OidcRegisteredService",
"clientId": "thestrapiclientid",
"clientSecret": "thestrapiclientsecret",
"bypassApprovalPrompt": true,
"serviceId": "^http(|s)://localhost:1337/.*",
"name": "Local Strapi",
"id": 20201103,
"evaluationOrder": 50,
"attributeReleasePolicy": {
"@class": "org.apereo.cas.services.ReturnMappedAttributeReleasePolicy",
"allowedAttributes": {
"@class": "java.util.TreeMap",
"strapiemail": "groovy { return attributes['mail'].get(0) }",
"strapiusername": "groovy { return attributes['username'].get(0) }"
}
}
}
Strapi 配置
- 访问 User & Permissions 提供方设置页面,地址为 http://localhost:1337/admin/settings/users-permissions/providers
- 点击 CAS 提供方
- 填写以下信息:
- Enable:
ON - Client ID:thestrapiclientid
- Client Secret:thestrapiclientsecret
- 指向你前端应用的重定向 URL:
http://localhost:1337/api/connect/cas/redirect - Provider Subdomain(提供方子域名),以便以下 URL 对你所针对的 CAS 部署是正确的:
authorize_url: https://[subdomain]/oidc/authorize access_url: https://[subdomain]/oidc/token profile_url: https://[subdomain]/oidc/profile例如,如果本地运行 CAS,其登录 URL 为:
https://localhost:8443/cas/login,则提供方子域名的值应为localhost:8443/cas。 - Enable:
你的配置已完成。启动后端和 react 登录示例应用,访问 http://localhost:3000 并尝试连接到你所配置的提供方。