Merge remote-tracking branch 'server/axel-usermanagement' into axel-usermanagement

This commit is contained in:
Axel Uhl committed 2014-10-22 13:10:28 +02:00
commit 750dfd5031
5 files changed
+56 -7

No files matched your search

@@ -4,6 +4,8 @@ shiro.loginUrl = /security/ui/Login.html
shiro.successUrl = /UserManagement.html
# Use Built-in Chache Manager
anyofroles = com.sap.sse.security.AnyOfRolesFilter
anyofroles.loginUrl = ../security/ui/Login.html
credentialsMatcher = org.apache.shiro.authc.credential.Sha256CredentialsMatcher
# base64 encoding, not hex in this example:
@@ -23,9 +25,11 @@ securityManager.sessionManager = $sessionManager
#securityManager.sessionManager.sessionIdCookie = $globalCookie
authc = com.sap.sse.security.CustomFilter
authc.loginUrl = /security/ui/Login.html
authc.loginUrl = ../security/ui/Login.html
authc.successUrl = /security/ui/UserManagement.html
roles.loginUrl = ../security/ui/Login.html
sessionDAO = org.apache.shiro.session.mgt.eis.EnterpriseCacheSessionDAO
securityManager.sessionManager.sessionDAO = $sessionDAO
@@ -41,5 +45,5 @@ securityManager.cacheManager = $cacheManager
# shiro.loginUrl above.
/security/ui/UserManagement.html = roles[admin]
/LeaderboardEditing.html = roles[admin],roles[eventmanager]
/AdminConsole.html = roles[admin],roles[eventmanager]
/LeaderboardEditing.html = anyofroles[admin,eventmanager]
/AdminConsole.html = anyofroles[admin,eventmanager]
+1 -1
View File
@@ -1,8 +1,8 @@
<?xml version="1.0" encoding="UTF-8"?>
<classpath>
<classpathentry kind="con" path="com.google.gwt.eclipse.core.GWT_CONTAINER"/>
<classpathentry kind="con" path="org.eclipse.pde.core.requiredPlugins"/>
<classpathentry kind="src" path="src"/>
<classpathentry kind="con" path="org.eclipse.jdt.launching.JRE_CONTAINER/org.eclipse.jdt.internal.debug.ui.launcher.StandardVMType/JavaSE-1.6"/>
<classpathentry kind="con" path="com.google.gwt.eclipse.core.GWT_CONTAINER"/>
<classpathentry kind="output" path="bin"/>
</classpath>
@@ -0,0 +1,46 @@
package com.sap.sse.security;
import java.io.IOException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import org.apache.shiro.subject.Subject;
import org.apache.shiro.web.filter.authz.RolesAuthorizationFilter;
/**
* Allows access if current user has at least one role of the specified list.
* <br/>
* Basically, it's the same as {@link RolesAuthorizationFilter} but using {@literal OR} instead
* of {@literal AND} on the specified roles.<p>
*
* This class has been copied from the stackoverflow post
* <a href="http://stackoverflow.com/questions/14980703/apache-shiro-allowing-multiple-roles-to-access-a-url-not-working">
* http://stackoverflow.com/questions/14980703/apache-shiro-allowing-multiple-roles-to-access-a-url-not-working</a>.
*
* @see RolesAuthorizationFilter
* @author Andy Belsky
*/
public class AnyOfRolesFilter extends RolesAuthorizationFilter {
@Override
public boolean isAccessAllowed(ServletRequest request, ServletResponse response,
Object mappedValue) throws IOException {
final Subject subject = getSubject(request, response);
final String[] rolesArray = (String[]) mappedValue;
if (rolesArray == null || rolesArray.length == 0) {
//no roles specified, so nothing to check - allow access.
return true;
}
for (String roleName : rolesArray) {
if (subject.hasRole(roleName)) {
return true;
}
}
return false;
}
}
@@ -102,7 +102,6 @@ public class SecurityServiceImpl extends RemoteServiceServlet implements Securit
logger.info("No users found, creating default user \"admin\" with password \"admin\"");
createSimpleUser("admin", "nobody@sapsailing.com", "admin", /* validationBaseURL */ null);
addRoleForUser("admin", DefaultRoles.ADMIN.getRolename());
addRoleForUser("admin", "moderator");
} catch (UserManagementException | MailException e) {
logger.log(Level.SEVERE, "Exception while creating default admin user", e);
}
@@ -25,14 +25,14 @@ public class SecurityResource extends AbstractSecurityResource {
@GET
@Path("/hello")
@Produces("application/json;charset=UTF-8")
public Response sayHello(){
public Response sayHello() {
return Response.ok("Hello!", MediaType.TEXT_PLAIN).build();
}
@POST
@Path("/login")
@Produces("application/json;charset=UTF-8")
public Response login(@FormParam("username") String username, @FormParam("password") String password){
public Response login(@FormParam("username") String username, @FormParam("password") String password) {
try {
getService().login(username, password);
logger.info("Successfully logged in " + username + " with password");