mirror of
https://github.com/eclipse-sailing-analytics/sailing-analytics.git
synced 2026-10-02 10:23:51 +00:00
Merge remote-tracking branch 'server/axel-usermanagement' into axel-usermanagement
This commit is contained in:
commit
750dfd5031
5 files changed
+56
-7
No files matched your search
@@ -4,6 +4,8 @@ shiro.loginUrl = /security/ui/Login.html
|
||||
shiro.successUrl = /UserManagement.html
|
||||
# Use Built-in Chache Manager
|
||||
|
||||
anyofroles = com.sap.sse.security.AnyOfRolesFilter
|
||||
anyofroles.loginUrl = ../security/ui/Login.html
|
||||
|
||||
credentialsMatcher = org.apache.shiro.authc.credential.Sha256CredentialsMatcher
|
||||
# base64 encoding, not hex in this example:
|
||||
@@ -23,9 +25,11 @@ securityManager.sessionManager = $sessionManager
|
||||
#securityManager.sessionManager.sessionIdCookie = $globalCookie
|
||||
|
||||
authc = com.sap.sse.security.CustomFilter
|
||||
authc.loginUrl = /security/ui/Login.html
|
||||
authc.loginUrl = ../security/ui/Login.html
|
||||
authc.successUrl = /security/ui/UserManagement.html
|
||||
|
||||
roles.loginUrl = ../security/ui/Login.html
|
||||
|
||||
sessionDAO = org.apache.shiro.session.mgt.eis.EnterpriseCacheSessionDAO
|
||||
securityManager.sessionManager.sessionDAO = $sessionDAO
|
||||
|
||||
@@ -41,5 +45,5 @@ securityManager.cacheManager = $cacheManager
|
||||
# shiro.loginUrl above.
|
||||
|
||||
/security/ui/UserManagement.html = roles[admin]
|
||||
/LeaderboardEditing.html = roles[admin],roles[eventmanager]
|
||||
/AdminConsole.html = roles[admin],roles[eventmanager]
|
||||
/LeaderboardEditing.html = anyofroles[admin,eventmanager]
|
||||
/AdminConsole.html = anyofroles[admin,eventmanager]
|
||||
@@ -1,8 +1,8 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<classpath>
|
||||
<classpathentry kind="con" path="com.google.gwt.eclipse.core.GWT_CONTAINER"/>
|
||||
<classpathentry kind="con" path="org.eclipse.pde.core.requiredPlugins"/>
|
||||
<classpathentry kind="src" path="src"/>
|
||||
<classpathentry kind="con" path="org.eclipse.jdt.launching.JRE_CONTAINER/org.eclipse.jdt.internal.debug.ui.launcher.StandardVMType/JavaSE-1.6"/>
|
||||
<classpathentry kind="con" path="com.google.gwt.eclipse.core.GWT_CONTAINER"/>
|
||||
<classpathentry kind="output" path="bin"/>
|
||||
</classpath>
|
||||
@@ -0,0 +1,46 @@
|
||||
package com.sap.sse.security;
|
||||
|
||||
import java.io.IOException;
|
||||
|
||||
import javax.servlet.ServletRequest;
|
||||
import javax.servlet.ServletResponse;
|
||||
|
||||
import org.apache.shiro.subject.Subject;
|
||||
import org.apache.shiro.web.filter.authz.RolesAuthorizationFilter;
|
||||
|
||||
/**
|
||||
* Allows access if current user has at least one role of the specified list.
|
||||
* <br/>
|
||||
* Basically, it's the same as {@link RolesAuthorizationFilter} but using {@literal OR} instead
|
||||
* of {@literal AND} on the specified roles.<p>
|
||||
*
|
||||
* This class has been copied from the stackoverflow post
|
||||
* <a href="http://stackoverflow.com/questions/14980703/apache-shiro-allowing-multiple-roles-to-access-a-url-not-working">
|
||||
* http://stackoverflow.com/questions/14980703/apache-shiro-allowing-multiple-roles-to-access-a-url-not-working</a>.
|
||||
*
|
||||
* @see RolesAuthorizationFilter
|
||||
* @author Andy Belsky
|
||||
*/
|
||||
public class AnyOfRolesFilter extends RolesAuthorizationFilter {
|
||||
|
||||
@Override
|
||||
public boolean isAccessAllowed(ServletRequest request, ServletResponse response,
|
||||
Object mappedValue) throws IOException {
|
||||
|
||||
final Subject subject = getSubject(request, response);
|
||||
final String[] rolesArray = (String[]) mappedValue;
|
||||
|
||||
if (rolesArray == null || rolesArray.length == 0) {
|
||||
//no roles specified, so nothing to check - allow access.
|
||||
return true;
|
||||
}
|
||||
|
||||
for (String roleName : rolesArray) {
|
||||
if (subject.hasRole(roleName)) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
}
|
||||
@@ -102,7 +102,6 @@ public class SecurityServiceImpl extends RemoteServiceServlet implements Securit
|
||||
logger.info("No users found, creating default user \"admin\" with password \"admin\"");
|
||||
createSimpleUser("admin", "nobody@sapsailing.com", "admin", /* validationBaseURL */ null);
|
||||
addRoleForUser("admin", DefaultRoles.ADMIN.getRolename());
|
||||
addRoleForUser("admin", "moderator");
|
||||
} catch (UserManagementException | MailException e) {
|
||||
logger.log(Level.SEVERE, "Exception while creating default admin user", e);
|
||||
}
|
||||
|
||||
@@ -25,14 +25,14 @@ public class SecurityResource extends AbstractSecurityResource {
|
||||
@GET
|
||||
@Path("/hello")
|
||||
@Produces("application/json;charset=UTF-8")
|
||||
public Response sayHello(){
|
||||
public Response sayHello() {
|
||||
return Response.ok("Hello!", MediaType.TEXT_PLAIN).build();
|
||||
}
|
||||
|
||||
@POST
|
||||
@Path("/login")
|
||||
@Produces("application/json;charset=UTF-8")
|
||||
public Response login(@FormParam("username") String username, @FormParam("password") String password){
|
||||
public Response login(@FormParam("username") String username, @FormParam("password") String password) {
|
||||
try {
|
||||
getService().login(username, password);
|
||||
logger.info("Successfully logged in " + username + " with password");
|
||||
|
||||
Reference in new issue
Block a user