Версия для печати темы
Нажмите сюда для просмотра этой темы в оригинальном формате
Форум программистов > Java EE (J2EE) и Spring > Стандартная аутентификация Sun App Server 9.01


Автор: Maverick 30.5.2007, 15:11
Подскажите, плиз... полдня бьюсь... Хочу для теста организовать стандартную аутентификацию... 

Запихал вот это в web-xml
Код

    <security-constraint>
        <display-name>ConstraintTest</display-name>
        <web-resource-collection>
            <web-resource-name>BankSite</web-resource-name>
            <description/>
            <url-pattern>/faces/*</url-pattern>
            <http-method>GET</http-method>
            <http-method>POST</http-method>
            <http-method>HEAD</http-method>
            <http-method>PUT</http-method>
            <http-method>OPTIONS</http-method>
            <http-method>TRACE</http-method>
            <http-method>DELETE</http-method>
        </web-resource-collection>
        <auth-constraint>
            <description/>
            <role-name>Test</role-name>
            </auth-constraint>
        <user-data-constraint>
            <description/>
            <transport-guarantee>CONFIDENTIAL</transport-guarantee>
        </user-data-constraint>
        </security-constraint>
    <login-config>
        <auth-method>BASIC</auth-method>
        <realm-name>maverick</realm-name>
        </login-config>
    <security-role>
        <description/>
        <role-name>Test</role-name>
    </security-role>
    </web-app>


и это в sun-web.xml
Код

  <context-root>/Bank-vwa</context-root>
  <security-role-mapping>
    <role-name>Test</role-name>
    <group-name>UITO</group-name>
  </security-role-mapping>


как видите, ограничил папк /faces/*... 

Теперь когда пытаюсь зайти на эти страницы - спрашивает пароль... Самое интересное - пароль и логин проверяет правильно... То есть нужного юзера пропускает, но демонстрирует не сам страницу, а сообщение...
Код

HTTP Status 403 - Access to the requested resource has been denied

type Status report

message Access to the requested resource has been denied

description Access to the specified resource (Access to the requested resource has been denied) has been forbidden.
Sun Java System Application Server Platform Edition 9.0_01


Что это может быть и как с этим бороться...

В логах сервера появляется это
Код

WEB0100: Loading web module [Bank:Bank-war.war] in virtual server [server] at [/Bank-war]
SEC5046: Audit: Authentication refused for [Maverick].
Web login failed: Login failed: javax.security.auth.login.LoginException: Security Exception
JACC Policy Provider: PolicyWrapper.implies, context(Bank/Bank-vwa_war)- permission((javax.security.jacc.WebUserDataPermission /faces/ListAccountBank.jsp GET)) domain that failed(ProtectionDomain  (file:/Bank/Bank-vwa_war <no signer certificates>)
 null
 <no principals>
 java.security.Permissions@bc1e7e (
 (java.util.PropertyPermission line.separator read)
 (java.util.PropertyPermission java.vm.version read)
 (java.util.PropertyPermission java.vm.specification.version read)
 (java.util.PropertyPermission java.vm.specification.vendor read)
 (java.util.PropertyPermission java.vendor.url read)
 (java.util.PropertyPermission java.vm.name read)
 (java.util.PropertyPermission * read)
 (java.util.PropertyPermission os.name read)
 (java.util.PropertyPermission java.vm.vendor read)
 (java.util.PropertyPermission path.separator read)
 (java.util.PropertyPermission java.specification.name read)
 (java.util.PropertyPermission os.version read)
 (java.util.PropertyPermission os.arch read)
 (java.util.PropertyPermission java.class.version read)
 (java.util.PropertyPermission java.version read)
 (java.util.PropertyPermission file.separator read)
 (java.util.PropertyPermission java.vendor read)
 (java.util.PropertyPermission java.vm.specification.name read)
 (java.util.PropertyPermission java.specification.version read)
 (java.util.PropertyPermission java.specification.vendor read)
 (javax.management.MBeanTrustPermission register)
 (javax.management.MBeanPermission [com.sun.messaging.jms.*:*] *)
 (javax.security.auth.PrivateCredentialPermission javax.resource.spi.security.PasswordCredential * "*" read)
 (java.net.SocketPermission localhost:1024- listen,resolve)
 (java.net.SocketPermission * connect,resolve)
 (unresolved javax.security.jacc.WebUserDataPermission /:/faces/* null)
 (unresolved javax.security.jacc.WebUserDataPermission /faces/* !DELETE,GET,HEAD,OPTIONS,POST,PUT,TRACE)
 (unresolved javax.security.jacc.WebUserDataPermission /faces/* DELETE,GET,HEAD,OPTIONS,POST,PUT,TRACE:CONFIDENTIAL)
 (unresolved javax.security.jacc.WebResourcePermission /:/faces/* null)
 (unresolved javax.security.jacc.WebResourcePermission /faces/* !DELETE,GET,HEAD,OPTIONS,POST,PUT,TRACE)
 (unresolved com.sun.enterprise.security.CORBAObjectPermission * *)
 (java.lang.RuntimePermission loadLibrary.*)
 (java.lang.RuntimePermission accessDeclaredMembers)
 (java.lang.RuntimePermission modifyThreadGroup)
 (java.lang.RuntimePermission stopThread)
 (java.lang.RuntimePermission queuePrintJob)
 (java.io.FilePermission C:\DOCUME~1\u0109\LOCALS~1\Temp\\- delete)
 (java.io.FilePermission E:/JavaTools/AppServer9.01/domains/domain1\lib\databases\- delete)
 (java.io.FilePermission <<ALL FILES>> read,write)
)
)



какие где права еще нужно прописать... самое интересное - в другом приложении, более простом работает нормально... Может быть это от того, что на странице используются JSF-компоненты всякие? 

Powered by Invision Power Board (http://www.invisionboard.com)
© Invision Power Services (http://www.invisionpower.com)