It appears that this is not possible as of yet for drupal CAS, but I thought I'd check in to be sure because it seems like a potentially useful feature to implement if cannot currently be done.

I have all my users and user roles stored on example.com which is both my drupal home page as well as my CAS server. (Is that wrong to do? My single SSL certificate is bound to example.com rather than cas.example.com... is there a setup workaround or helpful link describing one?)

site.example.com is running as a CAS client on a separate IP address using example.com as its CAS server

I have three different user types on my CAS server, and I plan on adding more later. When a CAS login occurs, is it possible for the CAS client that receives the user ticket to recognize which local user type a CAS user belongs to?

Better yet, is it possible to have user types passed between CAS sites with a CAS login rather than determining their roles locally and declaring all incoming logins as uniform "CAS users"?

Thanks for any input or advice! I am still relatively new to drupal.

~Jason

Comments

metzlerd’s picture

Not currently. Others have asked for this, and I've basically decided that we need to provide cas attribute support for the cas server module which might make this possible in the future. Patches for this are welcome, but it will likely be late summer before I get around to working on this.

bfroehle’s picture

Like David, I agree that this would be great to see, however I'm not going to have time in the next few months to devote to it.

bfroehle’s picture

Basic attribute support for CAS Server is underway in #1181310-7: Let cas_server module send attributes.

jpcurley25’s picture

Fantastic!

bfroehle’s picture

Status: Active » Postponed

I'm marking this as postponed until #1181310: Let cas_server module send attributes is resolved.

bfroehle’s picture

bfroehle’s picture

Title: Pass user roles on CAS login » Use Drupal roles returned by CAS Server
Version: 6.x-3.0 » 6.x-3.x-dev
Category: support » feature
Status: Postponed » Active

Rudimentary CAS Server attributes (including Drupal role support) is now in the 6.x-3.x-dev version of the module. Changing this issue status accordingly.

You may also want to consider using the CAS Attributes module which recently gained this support in #1400466: Combine cas attributes roles module.

bkosborne’s picture

Issue summary: View changes
Status: Active » Closed (outdated)

D6 is unsupported, no new dev will go towards the D6 version of the module. Both the D7 and D8 versions of the module support doing this.