有效用户的Tomcat安全约束

Ric*_*mon 6 java tomcat web-applications security-constraint

我正在尝试保护tomcat中的资源,以便只有"有效用户"(在域中具有有效登录名和密码的用户)才能访问它.它们不一定属于该领域的一个群体.我已尝试使用该<security-constraint>指令的许多组合但未成功.有任何想法吗?

Eli*_*ton 12

除了auth-constraint之外,您还要添加到security-constraint:

   <auth-constraint>
       <role-name>*</role-name>
   </auth-constraint>
Run Code Online (Sandbox Code Playgroud)

您需要在web-app中指定安全角色:

    <security-role>
        <role-name>*</role-name>
    </security-role>
Run Code Online (Sandbox Code Playgroud)


Dav*_*itz 1

tomcat中有多种领域实现——内存、数据库、JAAS等等。最容易配置(尽管不是最安全)内存的一个,它包含一个 XML 文件,通常位于 conf/tomcat-users.xml 下:

<tomcat-users>
  <user name="tomcat" password="tomcat" roles="tomcat" />
  <user name="role1"  password="tomcat" roles="role1"  />
  <user name="both"   password="tomcat" roles="tomcat,role1" />
</tomcat-users>
Run Code Online (Sandbox Code Playgroud)

领域配置位于上下文、主机或引擎配置下,如下所示:

<Realm className="org.apache.catalina.realm.MemoryRealm"
       pathname="conf/tomcat-users.xml" />
Run Code Online (Sandbox Code Playgroud)

然后,在 web.xml 中添加以下定义:

    <security-constraint>
            <web-resource-collection>
                    <web-resource-name>MRC Customer Care</web-resource-name>
                    <url-pattern>/protected/*</url-pattern>
            </web-resource-collection>
            <auth-constraint>
                    <role-name>role1</role-name>
            </auth-constraint>
    </security-constraint>

    <!-- Define the Login Configuration for this Application -->
    <login-config>
            <auth-method>DIGEST</auth-method>
            <realm-name>YOUR REALM NAME</realm-name>
    </login-config>

    <security-role>
            <description>
              The role that is required to access the application. 
              Should be on from the realm (the tomcat-users.xml file).
            </description>
            <role-name>role1</role-name>                  
    </security-role>
Run Code Online (Sandbox Code Playgroud)

web.xml 部分取自我们的一个 Web 应用程序(略有更改)。