tracks/app/views
Erik Ordway 5b431ef50a This allows CAS to work side by side with other Auth methods.
This is at least one issue with this

to logout of CAS you need session information but the logout method blows this away so I do the cas log out before the session is killed so the session persistest in rails.  Because I needed to move the CAS before filters into login_cas and out of the application to make it work side by side.   The user will still be logined into tracks even though their CAS session is closed as the session will still be there.

 def logout
    @user.forget_me if logged_in?
    cookies.delete :auth_token
    session['user_id'] = nil
    if ( SITE_CONFIG['authentication_schemes'].include? 'cas')  && session[:cas_user]
      CASClient::Frameworks::Rails::Filter.logout(self)
    else
      reset_session
      notify :notice, "You have been logged out of Tracks."
      redirect_to_login
    end
  end

The other issue I have with this is that:
I could not find a use case for having mixed auth when using CAS. The reason to move to CAS is that all your users use CAS all the time. Even for admin accounts. Moodle is a good example of this in that when you activate CAS the default is that you can now only access moodle via CAS. By allowing mixed auth and self signup you end up with a anyone (the public) being able to sign up for accounts.
2010-01-12 17:17:56 -08:00
..
contexts Missed some formatted_ helpers not covered by tests 2009-12-07 23:16:21 -05:00
data Cleaning up Prototype remnants and refactoring 2009-10-16 23:52:52 -04:00
feedlist Cleaning up Prototype remnants and refactoring 2009-10-16 23:52:52 -04:00
integrations last commit went wrong. sorry for the noise 2009-08-04 10:05:32 +02:00
layouts This allows CAS to work side by side with other Auth methods. 2010-01-12 17:17:56 -08:00
login This allows CAS to work side by side with other Auth methods. 2010-01-12 17:17:56 -08:00
notes Missed some formatted_ helpers not covered by tests 2009-12-07 23:16:21 -05:00
preferences fix #584 where the date at the top did not use the users timezone, but the servers timezone 2009-04-07 21:34:15 +02:00
projects Missed some formatted_ helpers not covered by tests 2009-12-07 23:16:21 -05:00
recurring_todos Recurring todos mostly working now 2009-09-13 12:00:28 -04:00
search Cleaning up Prototype remnants and refactoring 2009-10-16 23:52:52 -04:00
shared Autocompletion for predecessors working 2009-11-29 20:34:38 -05:00
sidebar tidy up the templates and the js in them 2009-03-27 17:03:18 +01:00
stats add cucumber for integration testing and add a feature for statistics 2009-04-13 22:26:20 +02:00
todos Show context on un-hidden successor. Fixes #964 2009-12-16 17:42:42 -05:00
users This allows CAS to work side by side with other Auth methods. 2010-01-12 17:17:56 -08:00