Commit Graph
153 Commits
Author SHA1 Message Date
Axel Uhl 6bd56de7f1 cleaned up shiro.ini stuff further, added more comments 2015-02-26 13:48:51 +01:00
Axel Uhl 1cc22d3858 added anyofroles filter declaration to default shiro.ini 2015-02-26 12:42:47 +01:00
Axel Uhl bd327fe876 added comments and cleaned up structure in com.sap.sse.security/resources/shiro.ini to make it a good copy template, too 2015-02-26 12:35:59 +01:00
Axel Uhl c196f48ad1 prepared the com.sap.sailing.server.gateway bundle for REST security, showing a commented example in shiro.ini for the /events service end point 2015-02-25 18:26:27 +01:00
Axel Uhl 6c5b4e9027 added documentation for the security REST API 2015-02-25 17:22:23 +01:00
Axel Uhl 21f76c6dc4 obsolete old bearer access token when a new one is obtained for the subject 2015-02-25 14:36:01 +01:00
Axel Uhl 837fce4a6c re-use subject instead of acquiring it freshly where possible 2015-02-25 12:32:01 +01:00
Axel Uhl 6ad8d92981 don't save the username in the SOCIAL_USER field; it can always be obtained by Subject.getPrincipal() 2015-02-25 12:28:23 +01:00
Axel Uhl ae9ca81f45 fixed launch configs regarding zxing bundle; added Javadoc 2015-02-25 09:37:41 +01:00
Axel Uhl 8d76c78c48 added missing class FormAuthenticationFilterWithPublicCreateToken which is a delegate for the bearer token authentication filter 2015-02-25 08:38:53 +01:00
Axel Uhl 6076f03c60 enhanced logon procedures and fixed test cases 2015-02-25 00:53:43 +01:00
Axel Uhl cf010e8c02 provide and use a BearerTokenAuthenticationFilter which defaults to HTTP basic authentication; renamed AccessTokenRealm to BearerTokenRealm 2015-02-24 21:58:02 +01:00
Axel Uhl 695ebe0be9 fixed media types for SecurityResource 2015-02-24 15:34:58 +01:00
Axel Uhl e70e605f79 Merge branch 'master' into bug2589 2015-02-23 18:25:45 +01:00
Axel Uhl 8762002794 made all gwt.osgi to gwt.dev dependencies optional 2015-02-23 18:25:11 +01:00
Axel Uhl a964dcda47 require authenticated user to create UserDTO 2015-02-17 18:12:00 +01:00
Axel Uhl 73f7ce197f whitespace changes only 2015-02-16 23:40:05 +01:00
Axel Uhl ef698c16a0 removed cherry-picked effects of permission management 2015-02-16 15:59:55 +01:00
Axel Uhl eaacd3f4c1 moved server-side QR code stuff from sse.common to sse because it's not GWT-compileable
Conflicts:
	java/com.sap.sailing.gwt.ui/src/main/java/com/sap/sailing/gwt/ui/client/shared/security/SailingPermissionsForRoleProvider.java
	java/com.sap.sse.security.common/src/com/sap/sse/security/shared/PermissionsForRoleProvider.java
	java/com.sap.sse.security/src/com/sap/sse/security/AbstractUserStoreBasedRealm.java
2015-02-16 15:58:18 +01:00
Axel Uhl 26b55ffd32 moved server-side QR code stuff from sse.common to sse because it's not GWT-compileable 2015-02-16 00:33:32 +01:00
Axel Uhl 559d2d25ed Merge branch 'master' into bug2589 2015-02-15 17:42:22 +01:00
Axel Uhl 39b1c55a88 made compileable after master mergeMerge branch 'master' into ftes-mail-move-to-sse
Conflicts:
	java/com.sap.sailing.server/SailingServer (No Proxy).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, Cached MTB).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8889).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8889, Cached MTB).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8890).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, Remote Debug SAP VM).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, winddbTest).launch
	java/com.sap.sailing.server/SailingServer (Proxy).launch
	java/com.sap.sailing.server/SailingServer (Proxy, Jetty on 8889).launch
	java/com.sap.sailing.server/SailingServer (Proxy, Remote Debug SAP VM).launch
	java/com.sap.sailing.server/SailingServer (Proxy, SwissTiming Live Simulation).launch
	java/com.sap.sailing.server/SailingServer (Proxy, winddbTest).launch
	java/com.sap.sse.security.test/META-INF/MANIFEST.MF
	java/com.sap.sse.security.test/src/com/sap/sse/security/test/LoginTest.java
	java/com.sap.sse.security/src/com/sap/sse/security/impl/Activator.java
	java/com.sap.sse.security/src/com/sap/sse/security/impl/SecurityServiceImpl.java
2015-02-14 21:23:24 +01:00
Axel Uhl f5d87fc908 set bundle context in com.sap.sse.security's Activator.start method right at the beginning 2015-02-13 23:21:20 +01:00
Fredrik Teschke 42e1411bb6 add replication test for mail service (could only test applying changes to master) 2015-02-13 20:30:32 +01:00
Axel Uhl 021b4a96ac replaced UserRoles.adminitsrator by DefaultRoles.ADMIN 2015-02-13 15:59:24 +01:00
Axel Uhl d041cece0c implemented AccessTokenRealm and added a first simple test case 2015-02-13 14:22:33 +01:00
Axel Uhl dabd2d3a98 fixed initialization of SecurityResourceTest whose first test around access token retrieval is now green 2015-02-13 13:52:05 +01:00
Axel Uhl 0800cab32a started with access token / REST security; test case read 2015-02-13 11:43:50 +01:00
Axel Uhl a1a8166b08 fixed MongoDB bundle reference in launch configurations after target platform upgrade 2015-02-13 10:18:32 +01:00
Axel Uhl ecc6ff8332 Merge branch 'master' into bug2589 2015-02-13 09:31:59 +01:00
Fredrik Teschke fa887140c8 Merge branch 'master' into ftes-mail-move-to-sse
Conflicts:
	java/com.sap.sailing.feature/feature.xml
	java/com.sap.sailing.server/SailingServer (No Proxy).launch
	java/com.sap.sailing.server/SailingServer (Proxy).launch
	java/com.sap.sse.security.ui/Security UI sdm.launch
	java/pom.xml
2015-02-12 18:14:21 +01:00
Axel Uhl 2269ea3096 starting to implement an access token generator 2015-02-12 17:23:08 +01:00
Fredrik Teschke f637d50c41 add old jackson bundle as dependency to MANIFESTS to avoid NoClassDefFoundErrors 2015-02-12 13:14:47 +01:00
Fredrik Teschke c6b68ee17b move MailException to common bundle (needed by GWT) 2015-02-09 22:36:55 +01:00
Fredrik Teschke e004c433cc pull out mail functionality into own service and bundle
- needs to live outside com.sap.sse due to dependency on replication
- use mail.properties instead of security.properties
- introduced ServiceTrackerFactory, which led to refactorings in SailingServiceImpl and ~Mock
2015-02-09 21:03:50 +01:00
Axel Uhl 7f7eb10256 move ObjectInputStreamResolvingAgainstCache to com.sap.sse and let com.sap.sse depend on com.sap.sse.common which has the IsManaagedByCache interface 2015-01-14 13:54:45 +01:00
Axel Uhl 24bba04589 moved ObjectInputStreamResolvingAgainstCache to com.sap.sse.common so that com.sap.sailing.domain does not require a dependency on com.sap.sse.replication anymore 2015-01-14 10:59:05 +01:00
Axel Uhl 163e7ca0f6 making the ThreadLocal objectcs instance variables in the Replicables helps the tests that failed due to a lack of isolation between the many Replicable objects in the same VM 2014-12-11 10:06:36 +01:00
Axel Uhl 64451c2702 fixing bug 2493; introduced a ThreadLocal telling whether replica is receiving initial load or running a master operation; not firing back to master if this flag is set 2014-12-11 09:57:18 +01:00
Axel Uhl b604ff0d37 solving bug 2428 by pulling up the doGetAuthorizationInfo method from UsernamePasswordRealm to AbstractUserStoreBasedReal, thus sharing it with OAuthRealm 2014-12-01 17:54:09 +01:00
Axel Uhl 6a8f4d4c89 added UI support for managing user permissions 2014-12-01 16:56:10 +01:00
Axel Uhl ebfb80479b SecurityService is now properly cleared (clearState()) at the beginning of Selenium test case executions 2014-12-01 16:18:58 +01:00
Axel Uhl 30cb8e7082 registering SecurityService as ClearStateTestSupport implementation 2014-12-01 16:01:51 +01:00
Axel Uhl 619a801f3e solution for bug 2427: permissions are now supported on User and related objects, including persistence and test case 2014-12-01 15:25:47 +01:00
Axel Uhl 8e7ab908e7 replicate operations initiated on replica to master and ignore them when they come back to that replica; see bug 2408 2014-11-29 23:50:06 +01:00
Axel Uhl 47abca3054 solving bug 2480 also for SecurityOperation implementations 2014-11-28 17:34:47 +01:00
Axel Uhl 672ca1b5c8 moved TimerWithRunnable to com.sap.sse and let com.sap.sse.security depend on it, allowing TimerWithRunnable to use Java8 features 2014-11-28 15:03:48 +01:00
Axel Uhl 565c9d9225 made the map storing the sessions scheduled for onChange notifications in a static instead of an instance map 2014-11-26 00:34:01 +01:00
Axel Uhl b3a0ba280f delay the sending of change notifications for a Session.touch() event 2014-11-25 21:43:42 +01:00
Axel Uhl b5b0c61b1c fixing Shiro session replication by not replacing the caches but replacing the cache contents;
Shiro seems to hold long-term references to the caches handed out by the CacheManager. Replacing those
caches during initial load doesn't help. They need to have their *contents* replaced instead.
2014-11-24 23:21:47 +01:00