CAS SSO with Activiti REST API

Question asked by einarwh on Oct 8, 2013
Latest reply on Oct 9, 2013 by einarwh

We're building a multi-component web application that communicates with Activiti using the REST API. We'd like to do two things:

1. Replace the default basic HTTP authentication, and rely on Tomcat to handle authentication using CAS SSO. We obviously still need a notion of identity for the user - should we use a suitable IdentityService for this?

2. Implement our own authorization scheme based on LDAP integration.

My understanding is that it is not sufficient to implement our own RestAuthenticator, since this will still employ the default authentication scheme.

Any pointers on how to best proceed would be greatly appreciated.

My apologies if my questions are naive or misguided, I am an Activiti beginner.

Kind regards,