II've found the issue. Just a problem with the curl command.... When validating the ticket, just need to use curl with '--url' option to encode the url (ST Id contains special characters like '-'.) Finally, the correct curl request is : curl -k --url " https://myhost.mydomain.fr/cas/p3/serviceValidate?service=myhost.mydomain &ticket=ST-4-vodW-DXn3MSrZh1IDJ182HTy7yI-myhost"
Thank you. Le jeudi 7 décembre 2023 à 16:54:02 UTC+1, Chris SC a écrit : > Hello, > I got an issue using REST. I can't validate a service ticket to get user's > attributes. > One of our service providers needs to authenticate our users with REST (it > works here), but impossible to get the attributes by validating the ticket. > (with /cas/p3/serviceValidate...) > The error is 'invalid ticket' ... yet I follow the instructions from > https://fawnoos.com/2019/06/12/cas61x-rest-api/ > If anyone can point me in the right direction ....you can see the logs.... > > Thank you > ----------------------- > *1/ Get a TGT : * > ----------------------- > *Actions : * > curl -k -X POST -H "Content-Type: Application/x-www-form-urlencoded" -H > "Accept: application/json" > https://myhost.mydomain.fr/cas/v1/tickets?service="service.mydomain.com" > -d "username=casuser&password=Mellon" > > > *TGT-4-Jop40r5OJhCmXxnufayW-nKMtcKpD58j9YbxG2WHDU2GLq6hBZPXdtAswNK7p34jR7A-myhost* > > *Logs : * > BEGIN > ============================================================= > WHO: casuser > WHAT: TGT-4-********p34jR7A-pccas02 > ACTION: TICKET_GRANTING_TICKET_CREATED > APPLICATION: CAS > WHEN: Thu Dec 07 16:00:37 CET 2023 > CLIENT IP ADDRESS: 172.16.6.26 > SERVER IP ADDRESS: 192.168.159.192 > ============================================================= > > BEGIN > ============================================================= > WHO: casuser > WHAT: {location= > https://myhost.mydomain.fr/cas/v1/tickets/TGT-4-********p34jR7A-myhost, > status=201-CREATED} > ACTION: REST_API_TICKET_GRANTING_TICKET_CREATED > APPLICATION: CAS > WHEN: Thu Dec 07 16:00:37 CET 2023 > CLIENT IP ADDRESS: 172.16.6.26 > SERVER IP ADDRESS: 192.168.159.192 > ============================================================= > > > ---------------------------- > *2/ Get a ST * > ----------------------- > curl -k -X POST -H "Content-Type: Application/x-www-form-urlencoded" -H > "Accept: application/json" > https://myhost.mydomain.fr/cas/v1/tickets/TGT-4-Jop40r5OJhCmXxnufayW-nKMtcKpD58j9YbxG2WHDU2GLq6hBZPXdtAswNK7p34jR7A-myhost?service= > "service.mydomain.com" > > *ST-4-vodW-DXn3MSrZh1IDJ182HTy7yI-myhost* > > ============================================================= > WHO: casuser > WHAT: {ticket=ST-4-********2HTy7yI-myhost, service=myhost.mydomain} > ACTION: SERVICE_TICKET_CREATED > APPLICATION: CAS > WHEN: Thu Dec 07 16:03:52 CET 2023 > CLIENT IP ADDRESS: 172.16.6.26 > SERVER IP ADDRESS: 192.168.159.192 > ============================================================= > > ============================================================= > WHO: casuser > WHAT: {body=ST-4-********2HTy7yI-myhost, status=200-OK} > ACTION: REST_API_SERVICE_TICKET_CREATED > APPLICATION: CAS > WHEN: Thu Dec 07 16:03:52 CET 2023 > CLIENT IP ADDRESS: 172.16.6.26 > SERVER IP ADDRESS: 192.168.159.192 > ============================================================= > > > *3/ (less than 10 seconds later) Ticket validation (to get user profile) : > * > > curl -k > https://myhost.mydomain.fr/cas/p3/serviceValidate?service=myhost.mydomain > "&"ticket=ST-4-vodW-DXn3MSrZh1IDJ182HTy7yI-myhost > > <cas:serviceResponse xmlns:cas='http://www.yale.edu/tp/cas'> > <cas:authenticationFailure code="INVALID_TICKET">Le ticket > 'ST-4-vodW-DXn3MSrZh1IDJ182HTy7yI-pccas02' est > inconnu</cas:authenticationFailure> > </cas:serviceResponse> > > ============================================================= > WHO: audit:unknown > WHAT: {ticket=ST-4-********2HTy7yI-myhost, service=myhost.mydomain} > ACTION: SERVICE_TICKET_VALIDATE_FAILED > APPLICATION: CAS > WHEN: Thu Dec 07 16:04:22 CET 2023 > CLIENT IP ADDRESS: 172.16.6.26 > SERVER IP ADDRESS: 192.168.159.192 > ============================================================= > -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/7168f2bf-9ad5-45f1-88a1-782268764dabn%40apereo.org.
