如何在Jboss7.1中配置简单身份验证

Dro*_*gba 8 java security jsp jboss7.x

我正在研究纯jsps(scriptlets)编写的项目,而不使用任何框架.

jboss版本:jboss-as-7.1.0.Final

我现在正在尝试添加简单的身份验证.因此,当用户尝试浏览jsps时http://localhost/myContextPath/hello.jsp,首先需要登录.

web.xml中

<security-constraint>
    <web-resource-collection>
        <web-resource-name>All Access</web-resource-name>
        <url-pattern>/*</url-pattern>
        <http-method>DELETE</http-method>
        <http-method>PUT</http-method>
        <http-method>HEAD</http-method>
        <http-method>OPTIONS</http-method>
        <http-method>TRACE</http-method>
        <http-method>GET</http-method>
        <http-method>POST</http-method>
    </web-resource-collection>
    <user-data-constraint>
        <transport-guarantee>CONFIDENTIAL</transport-guarantee>
    </user-data-constraint>
</security-constraint>
<login-config>
    <auth-method>BASIC</auth-method>
</login-config>
Run Code Online (Sandbox Code Playgroud)

的jboss-web.xml中

<jboss-web>
<security-domain>other</security-domain>
</jboss-web>
Run Code Online (Sandbox Code Playgroud)

standalone.xml([jboss_home]\standalone\configuration文件夹)

<subsystem xmlns="urn:jboss:domain:security:1.1">
        <security-domains>
            <security-domain name="other" cache-type="default">
                <authentication>
                    <login-module code="UsersRoles" flag="required">
                        <module-option name="usersProperties" value="users.properties"/>
                        <module-option name="rolesProperties" value="roles.properties"/>
                    </login-module>
                </authentication>
            </security-domain>
            <security-domain name="form-auth">
                <authentication>
                    <login-module code="UsersRoles" flag="required">
                        <module-option name="usersProperties" value="users.properties"/>
                        <module-option name="rolesProperties" value="roles.properties"/>
                    </login-module>
                </authentication>
            </security-domain>
        </security-domains>
    </subsystem>
Run Code Online (Sandbox Code Playgroud)

users.properties(放在webapp classes文件夹下)

user1=jboss7
Run Code Online (Sandbox Code Playgroud)

roles.properties(放在webapp classes文件夹下)

user1=Admin
Run Code Online (Sandbox Code Playgroud)

经过所有这些修改后,我尝试浏览我的hello jsp.我像往常一样工作.没有身份验证,也没有例外.

我不确定我是否朝着正确的方向前进,或者安全约束是完全不同的事情.请帮忙,谢谢!

chi*_*nto 11

只需按照本文的步骤设置7.1的BASIC身份验证.

试试这个.

组态

在web.xml

<security-constraint>
    <web-resource-collection>
        <web-resource-name>All Access</web-resource-name>
        <url-pattern>/*</url-pattern>
        <http-method>DELETE</http-method>
        <http-method>PUT</http-method>
        <http-method>HEAD</http-method>
        <http-method>OPTIONS</http-method>
        <http-method>TRACE</http-method>
        <http-method>GET</http-method>
        <http-method>POST</http-method>
    </web-resource-collection>
    <user-data-constraint>
        <transport-guarantee>CONFIDENTIAL</transport-guarantee>
    </user-data-constraint>
</security-constraint>
<login-config>
    <auth-method>BASIC</auth-method>
    <realm-name>ApplicationRealm</realm-name>
</login-config>

<security-role>
    <role-name>user</role-name>
</security-role>
Run Code Online (Sandbox Code Playgroud)

的jboss-web.xml中

<jboss-web>
    <security-domain>java:/jaas/other</security-domain>
</jboss-web>
Run Code Online (Sandbox Code Playgroud)

standalone.xml

如果您使用的是ApplicationRealm,则无需执行任何操作.

添加用户

您可以使用jboss提供的工具将用户添加到ApplicationRealm.

%JBOSS_HOME%/ bin开始.使用add-user.bat(或)add-user.sh工具.

C:\dev\jboss-eap-6.2\bin>add-user

What type of user do you wish to add?
 a) Management User (mgmt-users.properties)
 b) Application User (application-users.properties)
(a): b

Enter the details of the new user to add.
Using realm 'ApplicationRealm' as discovered from the existing property files.
Username : johngalt
Password :
Re-enter Password :
What groups do you want this user to belong to? (Please enter a comma separated list, or leave blank for none)[  ]: user
About to add user 'johngalt' for realm 'ApplicationRealm'
Is this correct yes/no? yes
Added user 'johngalt' to file 'C:\dev\jboss-eap-6.2\standalone\configuration\application-users.properties'
Added user 'johngalt' to file 'C:\dev\jboss-eap-6.2\domain\configuration\application-users.properties'
Added user 'johngalt' with groups user to file 'C:\dev\jboss-eap-6.2\standalone\configuration\application-roles.properties'
Added user 'johngalt' with groups user to file 'C:\dev\jboss-eap-6.2\domain\configuration\application-roles.properties'
Is this new user going to be used for one AS process to connect to another AS process?
e.g. for a slave host controller connecting to the master or for a Remoting connection for server to server EJB calls.
yes/no? no
Press any key to continue . . .

C:\dev\jboss-eap-6.2\bin>
Run Code Online (Sandbox Code Playgroud)

这对我有用