fixed SecurityServiceImpl constructor, not expecting the [urls] section to be present

This commit is contained in:
Axel Uhl committed 2014-10-14 15:16:01 +02:00
1 parent d32d4e0aef
commit afb57bd7b3
5 files changed
+55 -45

No files matched your search

@@ -1,7 +1,5 @@
package com.sap.sse.security.ui.usermanagement;
import java.util.HashMap;
import com.google.gwt.core.client.EntryPoint;
import com.google.gwt.core.client.GWT;
import com.google.gwt.dom.client.Style.Unit;
@@ -12,7 +10,6 @@ import com.google.gwt.event.dom.client.ClickHandler;
import com.google.gwt.user.cellview.client.SimplePager;
import com.google.gwt.user.cellview.client.SimplePager.TextLocation;
import com.google.gwt.user.client.Window;
import com.google.gwt.user.client.rpc.AsyncCallback;
import com.google.gwt.user.client.rpc.ServiceDefTarget;
import com.google.gwt.user.client.ui.Button;
import com.google.gwt.user.client.ui.DockLayoutPanel;
@@ -40,9 +37,7 @@ import com.sap.sse.security.ui.client.component.SettingsPanel;
import com.sap.sse.security.ui.client.component.UserDetailsView;
import com.sap.sse.security.ui.client.component.UserList;
import com.sap.sse.security.ui.client.component.UserListDataProvider;
import com.sap.sse.security.ui.loginpanel.EntryPointLinkFactory;
import com.sap.sse.security.ui.loginpanel.LoginPanel;
import com.sap.sse.security.ui.shared.SuccessInfo;
import com.sap.sse.security.ui.shared.UserDTO;
import com.sap.sse.security.ui.shared.UserManagementService;
import com.sap.sse.security.ui.shared.UserManagementServiceAsync;
@@ -57,6 +52,8 @@ public class UserManagementEntryPoint implements EntryPoint {
private TextBox filterBox = new TextBox();
private UserDTO user;
private ProvidesKey<UserDTO> keyProvider = new ProvidesKey<UserDTO>() {
public Object getKey(UserDTO item) {
// Always do a null check.
@@ -81,18 +78,10 @@ public class UserManagementEntryPoint implements EntryPoint {
userService.addUserStatusEventHandler(new UserStatusEventHandler() {
@Override
public void onUserStatusChange(UserDTO user) {
if (user == null){
userManagementService.logout(new AsyncCallback<SuccessInfo>() {
@Override
public void onFailure(Throwable caught) {
}
@Override
public void onSuccess(SuccessInfo result) {
}
});
Window.Location.replace(EntryPointLinkFactory.createLoginLink(new HashMap<String, String>()));
if (user == null && UserManagementEntryPoint.this.user != null) {
Window.Location.reload();
}
UserManagementEntryPoint.this.user = user;
}
});
Button createButton = new Button(stringMessages.createUser(), new ClickHandler() {
@@ -143,7 +132,6 @@ public class UserManagementEntryPoint implements EntryPoint {
ScrollPanel scrollPanel = new ScrollPanel(userList);
VerticalPanel vp = new VerticalPanel();
filterBox.addChangeHandler(new ChangeHandler() {
@Override
public void onChange(ChangeEvent event) {
userListDataProvider.updateDisplays();
+39
View File
@@ -0,0 +1,39 @@
[main]
#shiro.loginUrl = /security/ui/Login.html
#shiro.successUrl = /UserManagement.html
# Use Built-in Chache Manager
credentialsMatcher = org.apache.shiro.authc.credential.Sha256CredentialsMatcher
# base64 encoding, not hex in this example:
credentialsMatcher.storedCredentialsHexEncoded = false
credentialsMatcher.hashIterations = 1024
upRealm = com.sap.sse.security.UsernamePasswordRealm
upRealm.credentialsMatcher = $credentialsMatcher
oauthRealm = com.sap.sse.security.OAuthRealm
securityManager.realms = $upRealm, $oauthRealm
sessionManager = com.sap.sse.security.SecurityWebSessionManager
securityManager.sessionManager = $sessionManager
#globalCookie = com.sap.sse.security.GlobalCookie
#securityManager.sessionManager.sessionIdCookie = $globalCookie
authc = com.sap.sse.security.CustomFilter
authc.loginUrl = /security/ui/Login.html
authc.successUrl = /UserManagement.html
sessionDAO = org.apache.shiro.session.mgt.eis.EnterpriseCacheSessionDAO
securityManager.sessionManager.sessionDAO = $sessionDAO
cacheManager = com.sap.sse.security.SessionCacheManager
securityManager.cacheManager = $cacheManager
#securityManager.sessionMode = native
[urls]
/Login.html = anon
/UserManagement.html = authc,roles[admin]
+2 -20
View File
@@ -1,11 +1,8 @@
[main]
#shiro.loginUrl = /security/ui/Login.html
#shiro.successUrl = /UserManagement.html
# Use Built-in Chache Manager
# Use Built-in Cache Manager
credentialsMatcher = org.apache.shiro.authc.credential.Sha256CredentialsMatcher
# base64 encoding, not hex in this example:
credentialsMatcher.storedCredentialsHexEncoded = false
credentialsMatcher.hashIterations = 1024
@@ -19,8 +16,6 @@ securityManager.realms = $upRealm, $oauthRealm
sessionManager = com.sap.sse.security.SecurityWebSessionManager
securityManager.sessionManager = $sessionManager
#globalCookie = com.sap.sse.security.GlobalCookie
#securityManager.sessionManager.sessionIdCookie = $globalCookie
authc = com.sap.sse.security.CustomFilter
authc.loginUrl = /security/ui/Login.html
@@ -32,17 +27,4 @@ securityManager.sessionManager.sessionDAO = $sessionDAO
cacheManager = com.sap.sse.security.SessionCacheManager
securityManager.cacheManager = $cacheManager
#securityManager.sessionMode = native
[urls]
# The /login.jsp is not restricted to authenticated users (otherwise no one could log in!), but
# the 'authc' filter must still be specified for it so it can process that url's
# login submissions. It is 'smart' enough to allow those requests through as specified by the
# shiro.loginUrl above.
#/security/ui/UserManagement.html = authc
#/ui/UserManagement.html = authc
/Login.html = anon
#/../../service/** = anon
#/UserManagement.html = authc
@@ -61,14 +61,12 @@ public class OAuthRealm extends AbstractUserStoreBasedRealm {
@Override
public Collection<String> getStringPermissions() {
// TODO Auto-generated method stub
return new ArrayList<String>();
}
@Override
public Collection<String> getRoles() {
ArrayList<String> roles = new ArrayList<>();
roles.add("admin");
return roles;
}
@@ -76,7 +74,6 @@ public class OAuthRealm extends AbstractUserStoreBasedRealm {
public Collection<Permission> getObjectPermissions() {
ArrayList<Permission> permissions = new ArrayList<>();
permissions.add(new Permission() {
@Override
public boolean implies(Permission arg0) {
return false;
@@ -31,6 +31,7 @@ import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.cache.CacheManager;
import org.apache.shiro.cache.ehcache.EhCacheManager;
import org.apache.shiro.config.Ini;
import org.apache.shiro.config.Ini.Section;
import org.apache.shiro.crypto.RandomNumberGenerator;
import org.apache.shiro.crypto.SecureRandomNumberGenerator;
import org.apache.shiro.crypto.hash.Sha256Hash;
@@ -107,11 +108,14 @@ public class SecurityServiceImpl extends RemoteServiceServlet implements Securit
Factory<SecurityManager> factory = new WebIniSecurityManagerFactory(shiroConfiguration);
logger.info("Loaded shiro.ini file from: classpath:shiro.ini");
StringBuilder logMessage = new StringBuilder("[urls] section from Shiro configuration:");
for (Entry<String, String> e : shiroConfiguration.getSection("urls").entrySet()) {
logMessage.append("\n");
logMessage.append(e.getKey());
logMessage.append(": ");
logMessage.append(e.getValue());
final Section urlsSection = shiroConfiguration.getSection("urls");
if (urlsSection != null) {
for (Entry<String, String> e : urlsSection.entrySet()) {
logMessage.append("\n");
logMessage.append(e.getKey());
logMessage.append(": ");
logMessage.append(e.getValue());
}
}
logger.info(logMessage.toString());
System.setProperty("java.net.useSystemProxies", "true");