<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Georgia;
panose-1:2 4 5 2 5 4 5 2 3 3;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:Consolas;}
p.CodeStyle, li.CodeStyle, div.CodeStyle
{mso-style-name:CodeStyle;
mso-style-link:"CodeStyle Char";
margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Georgia",serif;}
span.CodeStyleChar
{mso-style-name:"CodeStyle Char";
mso-style-link:CodeStyle;
font-family:"Georgia",serif;}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:Consolas;}
span.EmailStyle21
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Background- I’m upgrading from 3.4.7 to 4.2.1.<br>
We use the in-memory account lockout feature but found that the admin REST interface to manage lockouts doesn’t provide enough in its GET output. We wanted to have the ability to list all of the current lockouts so that we didn’t need to know the exact lockout
key. So I created my own “DoLockoutManagerOperation” bean and injected into the IdP via an extension. I believe that order to make it work, I had to effectively copy the entire admin/lockout flow XML files into my jar file because simply creating another
DoLockoutManagerOperation bean in my postconfig.xml or classpath:/net/shibboleth/idp/flows/admin/lockout-beans.xml or even in global.xml wasn’t enough.<o:p></o:p></p>
<p class="MsoNormal"><br>
This stuff now doesn’t work in 4.2.1. I’m getting an error that effectively prevents the IdP from even deploying….an error that looks like this:<br>
<br>
<o:p></o:p></p>
<p class="MsoNormal"><b>java.lang.IllegalStateException: Illegal attempt to register pre-existing flow ID 'admin/lockout'via resource: URL [jar:file:/opt/apache-tomcat-9.0.68/webapps/idp/WEB-INF/lib/mis-security-shibboleth.jar!/META-INF/net/shibboleth/idp/flows/admin/lockout/lockout-flow.xml<o:p></o:p></b></p>
<p class="MsoNormal"><b><o:p> </o:p></b></p>
<p class="MsoNormal">Is there not any way to override the admin flows in 4.x? How can I override the “DoLockoutManagerOperation” bean and inject in my own version that provides more JSON?<o:p></o:p></p>
<p class="MsoNormal">Thanks in advance Scott <span style="font-family:Wingdings">
J</span><o:p></o:p></p>
</div>
</body>
</html>