Skip to content

Replace Entra sign-in with Princeton CAS - #23

Merged
DIodide merged 1 commit into
mainfrom
feat/princeton-cas-auth
Sep 27, 2026
Merged

DIodide merged 1 commit into
mainfrom
feat/princeton-cas-auth

Conversation

@DIodide

@DIodide DIodide commented Sep 27, 2026

Copy link
Copy Markdown
Member

PI now signs students in through Princeton CAS and uses the validated CAS NetID for chat ownership. This removes the Entra client secret requirement and the OIT email-alias lookup.

  • Validate CAS 3.0 tickets over HTTPS with browser-bound state, the exact service URL, a timeout, and no validation redirects.
  • Keep signed, HttpOnly seven-day sessions; require existing Entra sessions to sign in again. Use CAS display name/email attributes when available.
  • Remove Entra/OIT configuration, document CAS setup and local-only logout, and run auth tests in CI.

Validation: 29 auth tests pass, TypeScript passes, and the production build passes. Princeton's live CAS endpoint returns the expected JSON rejection for an invalid ticket, and its login page accepts PI's callback URL with state. A complete student login still requires a Princeton account.

Deployment uses the existing SESSION_SECRET; CAS needs no application client secret. Existing NetID-owned chats retain their namespaces. Historical email-alias namespaces are not automatically reassigned.

@DIodide
DIodide merged commit 8affc63 into main Sep 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant