Axel Uhl
32daae4ad3
where concurrency support plays a role, changed field declarations from ConcurrentHashMap to ConcurrentMap which is sufficiently specific
...
Change-Id: I71254d96d495a1a8d79e009d70fd8928b720b31e
2016-06-07 17:08:07 +02:00
Axel Uhl
913fbe5d76
increased Shiro session manager timeout from 30min to 24h
...
Change-Id: I8bdcbc5b3c2658858643b3a4f04dfa83a571659a
2016-04-20 18:00:19 +02:00
Axel Uhl
3d25d4537d
use a dedicated authentication filter that provides an application name so the HTTP response's WWW-Authentication header shows it
...
Change-Id: I81f43969acb0aeada3bdb5b6f066c62aa00d0de6
2016-03-08 21:47:53 +01:00
Axel Uhl
2bae2dc265
fixed token generation for QR code; required getOrCreateAccessToken instead of only getAccessToken
...
Change-Id: Id7817e8f2c7939b088689acb3ac9b9ae42638643
2016-03-03 15:15:04 +01:00
Axel Uhl
44c37b4c32
fixed SecurityResourceTest, now removing existing token when requiring creation of new one
...
Change-Id: I1e8a5be5f7659ba0bff2841bed02033139de1b8a
2016-03-02 10:59:54 +01:00
Axel Uhl
524abc1124
secure the RaceLog POST servlet, requiring LEADERBOARD.UPDATE; fixed auth token loading in UserStore;
...
added removeAccessToken with remove_access_token end point on SecurityResource, available for ADMIN role
and owner
2016-03-02 00:09:54 +01:00
Axel Uhl
c356c2f97c
Merge branch 'master' into bug2589
...
Conflicts:
java/com.sap.sailing.domain.common/src/com/sap/sailing/domain/common/security/Permission.java
java/com.sap.sailing.domain.common/src/com/sap/sailing/domain/common/security/SailingPermissionsForRoleProvider.java
Change-Id: I3aaf2651c01460dd2fb0caf95735b9919586a2c9
2016-03-01 16:47:00 +01:00
Benjamin Barth
842d64d5e5
Added parameters full name and company to
...
UserManagementService.createSimpleUser method
2016-01-21 16:28:04 +01:00
Axel Uhl
432c979135
Merge branch 'master' into bug2589
...
Conflicts:
java/com.sap.sailing.server.gateway/src/com/sap/sailing/server/gateway/jaxrs/api/EventsResource.java
Change-Id: I63f05a28bdf63a0c6b7731e03c36b28b61e4638e
2016-01-12 14:28:13 +01:00
Axel Uhl
f91153d93c
cleaned up the ClientUtils implementation and removed unused OAuth cruft; removed GWT dependency from com.sap.sse.security;
...
removed RemoteServiceServlet superclass from SecurityServiceImpl; why was it there? The GWT RPC is implemented by
UserManagementServiceImpl
Change-Id: Ifc2e1f848b9fb5d7f24398a0497d301b037a822e
2016-01-12 09:43:07 +01:00
Axel Uhl
4e0c3f7073
providing update feature for additional User properties in SecurityService and UserManagementService
...
Change-Id: I46a4c2c58e35595dc20b85575a27c1cfbd639592
2016-01-12 09:28:23 +01:00
Axel Uhl
fb3f74d297
added fields fullName and company to User
...
Change-Id: I831b2a229c29081aab8f79174caa8d1900303b67
2016-01-12 09:13:01 +01:00
Axel Uhl
8246a64a3f
using UriUtils.fromString to avoid XSS security vulnerability
...
Change-Id: Ia6aada15502dd1e4e6a53cf9e6067fbea6a07fef
2016-01-08 11:01:54 +01:00
Axel Uhl
6169f54e25
Merge branch 'master' into bug2589
...
Conflicts:
java/com.sap.sailing.domain.igtimiadapter/META-INF/MANIFEST.MF
java/com.sap.sailing.gwt.ui/src/main/java/com/sap/sailing/gwt/ui/server/SailingServiceImpl.java
java/com.sap.sailing.server.gateway/META-INF/MANIFEST.MF
java/com.sap.sailing.server.gateway/src/com/sap/sailing/server/gateway/jaxrs/RestServletContainer.java
java/com.sap.sailing.server.gateway/src/com/sap/sailing/server/gateway/jaxrs/api/RestApiApplication.java
Change-Id: I8cbb797ba64d221ea401b90b22d21a813204a6f2
2016-01-04 11:34:01 +01:00
Axel Uhl
374bad01d8
use SecureRandom for user e-mail validation token generation
2015-12-08 12:46:56 +01:00
Frederik Petersen
883ef38d90
Now logging when tracked race is connected with race column
...
also loggin which user linked the race.
2015-07-21 15:47:20 +02:00
Axel Uhl
a9f43bf2f3
fixing bug 2849 by fixing the mismatch of username vs. e-mail address parameter semantics for MailService.sendMail
2015-05-12 22:19:31 +02:00
Axel Uhl
041b50cc3d
introduced Jersey ExceptionMapper for Shiro's AuthorizationException
2015-02-26 17:26:45 +01:00
Axel Uhl
6bd56de7f1
cleaned up shiro.ini stuff further, added more comments
2015-02-26 13:48:51 +01:00
Axel Uhl
1cc22d3858
added anyofroles filter declaration to default shiro.ini
2015-02-26 12:42:47 +01:00
Axel Uhl
bd327fe876
added comments and cleaned up structure in com.sap.sse.security/resources/shiro.ini to make it a good copy template, too
2015-02-26 12:35:59 +01:00
Axel Uhl
c196f48ad1
prepared the com.sap.sailing.server.gateway bundle for REST security, showing a commented example in shiro.ini for the /events service end point
2015-02-25 18:26:27 +01:00
Axel Uhl
6c5b4e9027
added documentation for the security REST API
2015-02-25 17:22:23 +01:00
Axel Uhl
21f76c6dc4
obsolete old bearer access token when a new one is obtained for the subject
2015-02-25 14:36:01 +01:00
Axel Uhl
837fce4a6c
re-use subject instead of acquiring it freshly where possible
2015-02-25 12:32:01 +01:00
Axel Uhl
6ad8d92981
don't save the username in the SOCIAL_USER field; it can always be obtained by Subject.getPrincipal()
2015-02-25 12:28:23 +01:00
Axel Uhl
ae9ca81f45
fixed launch configs regarding zxing bundle; added Javadoc
2015-02-25 09:37:41 +01:00
Axel Uhl
8d76c78c48
added missing class FormAuthenticationFilterWithPublicCreateToken which is a delegate for the bearer token authentication filter
2015-02-25 08:38:53 +01:00
Axel Uhl
6076f03c60
enhanced logon procedures and fixed test cases
2015-02-25 00:53:43 +01:00
Axel Uhl
cf010e8c02
provide and use a BearerTokenAuthenticationFilter which defaults to HTTP basic authentication; renamed AccessTokenRealm to BearerTokenRealm
2015-02-24 21:58:02 +01:00
Axel Uhl
695ebe0be9
fixed media types for SecurityResource
2015-02-24 15:34:58 +01:00
Axel Uhl
e70e605f79
Merge branch 'master' into bug2589
2015-02-23 18:25:45 +01:00
Axel Uhl
8762002794
made all gwt.osgi to gwt.dev dependencies optional
2015-02-23 18:25:11 +01:00
Axel Uhl
a964dcda47
require authenticated user to create UserDTO
2015-02-17 18:12:00 +01:00
Axel Uhl
73f7ce197f
whitespace changes only
2015-02-16 23:40:05 +01:00
Axel Uhl
ef698c16a0
removed cherry-picked effects of permission management
2015-02-16 15:59:55 +01:00
Axel Uhl
eaacd3f4c1
moved server-side QR code stuff from sse.common to sse because it's not GWT-compileable
...
Conflicts:
java/com.sap.sailing.gwt.ui/src/main/java/com/sap/sailing/gwt/ui/client/shared/security/SailingPermissionsForRoleProvider.java
java/com.sap.sse.security.common/src/com/sap/sse/security/shared/PermissionsForRoleProvider.java
java/com.sap.sse.security/src/com/sap/sse/security/AbstractUserStoreBasedRealm.java
2015-02-16 15:58:18 +01:00
Axel Uhl
26b55ffd32
moved server-side QR code stuff from sse.common to sse because it's not GWT-compileable
2015-02-16 00:33:32 +01:00
Axel Uhl
559d2d25ed
Merge branch 'master' into bug2589
2015-02-15 17:42:22 +01:00
Axel Uhl
39b1c55a88
made compileable after master mergeMerge branch 'master' into ftes-mail-move-to-sse
...
Conflicts:
java/com.sap.sailing.server/SailingServer (No Proxy).launch
java/com.sap.sailing.server/SailingServer (No Proxy, Cached MTB).launch
java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8889).launch
java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8889, Cached MTB).launch
java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8890).launch
java/com.sap.sailing.server/SailingServer (No Proxy, Remote Debug SAP VM).launch
java/com.sap.sailing.server/SailingServer (No Proxy, winddbTest).launch
java/com.sap.sailing.server/SailingServer (Proxy).launch
java/com.sap.sailing.server/SailingServer (Proxy, Jetty on 8889).launch
java/com.sap.sailing.server/SailingServer (Proxy, Remote Debug SAP VM).launch
java/com.sap.sailing.server/SailingServer (Proxy, SwissTiming Live Simulation).launch
java/com.sap.sailing.server/SailingServer (Proxy, winddbTest).launch
java/com.sap.sse.security.test/META-INF/MANIFEST.MF
java/com.sap.sse.security.test/src/com/sap/sse/security/test/LoginTest.java
java/com.sap.sse.security/src/com/sap/sse/security/impl/Activator.java
java/com.sap.sse.security/src/com/sap/sse/security/impl/SecurityServiceImpl.java
2015-02-14 21:23:24 +01:00
Axel Uhl
f5d87fc908
set bundle context in com.sap.sse.security's Activator.start method right at the beginning
2015-02-13 23:21:20 +01:00
Fredrik Teschke
42e1411bb6
add replication test for mail service (could only test applying changes to master)
2015-02-13 20:30:32 +01:00
Axel Uhl
021b4a96ac
replaced UserRoles.adminitsrator by DefaultRoles.ADMIN
2015-02-13 15:59:24 +01:00
Axel Uhl
d041cece0c
implemented AccessTokenRealm and added a first simple test case
2015-02-13 14:22:33 +01:00
Axel Uhl
dabd2d3a98
fixed initialization of SecurityResourceTest whose first test around access token retrieval is now green
2015-02-13 13:52:05 +01:00
Axel Uhl
0800cab32a
started with access token / REST security; test case read
2015-02-13 11:43:50 +01:00
Axel Uhl
a1a8166b08
fixed MongoDB bundle reference in launch configurations after target platform upgrade
2015-02-13 10:18:32 +01:00
Axel Uhl
ecc6ff8332
Merge branch 'master' into bug2589
2015-02-13 09:31:59 +01:00
Fredrik Teschke
fa887140c8
Merge branch 'master' into ftes-mail-move-to-sse
...
Conflicts:
java/com.sap.sailing.feature/feature.xml
java/com.sap.sailing.server/SailingServer (No Proxy).launch
java/com.sap.sailing.server/SailingServer (Proxy).launch
java/com.sap.sse.security.ui/Security UI sdm.launch
java/pom.xml
2015-02-12 18:14:21 +01:00
Axel Uhl
2269ea3096
starting to implement an access token generator
2015-02-12 17:23:08 +01:00