Issue 12572

Single sign in does not work in Drupal

12572
Reporter: kbraak
Type: Bug
Summary: Single sign in does not work in Drupal
Priority: Major
Resolution: WontFix
Status: Closed
Created: 2012-12-21 16:16:03.872
Updated: 2013-09-02 13:46:31.794
Resolved: 2013-02-18 16:45:11.582
        
Description: To replicate issue:

1) Visit https://cas.gbif.org//login?service=http://staging.gbif.org:8080/portal-web-dynamic/dataset/?url=dataset
2) Use your existing CAS account to login

What is the problem?

The problem is, that once logged in to staging Portal, the user needs to login to Drupal as well (see screenshot shown).

The inverse is not true. That is, once logged in to Drupal, the user does not need to login to staging Portal.

The goal: single sign-on!

Issue is raised here too: http://dev.gbif.org/wiki/display/POR/CAS+Security#CASSecurity-Drupalintegration]]>
    

Attachment Screen Shot 2013-01-17 at 2.38.59 PM.png



Author: jcuadra@gbif.org
Created: 2013-01-17 17:27:01.619
Updated: 2013-01-17 17:27:01.619
        
As pointed out in the http://dev.gbif.org/wiki/display/POR/CAS+Security#CASSecurity-Drupalintegration, which we can trace the issue to a drupal issue at:
http://drupal.org/node/1280474, it seems people have been offerring patches but not much activity from the moderators.

From our Drupal installation, I see we are using the CAS plugin version = 7.x-1.2

But I *think* we might benefit from trying the module's dev version at: http://drupal.org/node/952298 which might include some of these patches. I don't know much about the risk of installing a dev-version in the Drupal world, so maybe somebody else could offer suggestions?

We might also wait for this release to become a stable one, as this single-sign-on bug I think is not too dangerous for us at the moment
    


Author: kbraak@gbif.org
Comment: Interesting note, single sign-out is only supported in the latest dev, therefore not supported in 7.x-1.2: http://drupal.org/node/1569760
Created: 2013-01-18 17:06:28.468
Updated: 2013-01-18 17:06:28.468


Author: mdoering@gbif.org
Comment: we removed CAS, so this is not of interest anymore
Created: 2013-02-18 16:45:11.611
Updated: 2013-02-18 16:45:11.611