Axel Uhl
6bd56de7f1
cleaned up shiro.ini stuff further, added more comments
2015-02-26 13:48:51 +01:00
Axel Uhl
1cc22d3858
added anyofroles filter declaration to default shiro.ini
2015-02-26 12:42:47 +01:00
Axel Uhl
bd327fe876
added comments and cleaned up structure in com.sap.sse.security/resources/shiro.ini to make it a good copy template, too
2015-02-26 12:35:59 +01:00
Axel Uhl
c196f48ad1
prepared the com.sap.sailing.server.gateway bundle for REST security, showing a commented example in shiro.ini for the /events service end point
2015-02-25 18:26:27 +01:00
Axel Uhl
6c5b4e9027
added documentation for the security REST API
2015-02-25 17:22:23 +01:00
Axel Uhl
21f76c6dc4
obsolete old bearer access token when a new one is obtained for the subject
2015-02-25 14:36:01 +01:00
Axel Uhl
837fce4a6c
re-use subject instead of acquiring it freshly where possible
2015-02-25 12:32:01 +01:00
Axel Uhl
6ad8d92981
don't save the username in the SOCIAL_USER field; it can always be obtained by Subject.getPrincipal()
2015-02-25 12:28:23 +01:00
Axel Uhl
ae9ca81f45
fixed launch configs regarding zxing bundle; added Javadoc
2015-02-25 09:37:41 +01:00
Axel Uhl
8d76c78c48
added missing class FormAuthenticationFilterWithPublicCreateToken which is a delegate for the bearer token authentication filter
2015-02-25 08:38:53 +01:00
Axel Uhl
6076f03c60
enhanced logon procedures and fixed test cases
2015-02-25 00:53:43 +01:00
Axel Uhl
cf010e8c02
provide and use a BearerTokenAuthenticationFilter which defaults to HTTP basic authentication; renamed AccessTokenRealm to BearerTokenRealm
2015-02-24 21:58:02 +01:00
Axel Uhl
695ebe0be9
fixed media types for SecurityResource
2015-02-24 15:34:58 +01:00
Axel Uhl
e70e605f79
Merge branch 'master' into bug2589
2015-02-23 18:25:45 +01:00
Axel Uhl
8762002794
made all gwt.osgi to gwt.dev dependencies optional
2015-02-23 18:25:11 +01:00
Axel Uhl
a964dcda47
require authenticated user to create UserDTO
2015-02-17 18:12:00 +01:00
Axel Uhl
73f7ce197f
whitespace changes only
2015-02-16 23:40:05 +01:00
Axel Uhl
ef698c16a0
removed cherry-picked effects of permission management
2015-02-16 15:59:55 +01:00
Axel Uhl
eaacd3f4c1
moved server-side QR code stuff from sse.common to sse because it's not GWT-compileable
...
Conflicts:
java/com.sap.sailing.gwt.ui/src/main/java/com/sap/sailing/gwt/ui/client/shared/security/SailingPermissionsForRoleProvider.java
java/com.sap.sse.security.common/src/com/sap/sse/security/shared/PermissionsForRoleProvider.java
java/com.sap.sse.security/src/com/sap/sse/security/AbstractUserStoreBasedRealm.java
2015-02-16 15:58:18 +01:00
Axel Uhl
26b55ffd32
moved server-side QR code stuff from sse.common to sse because it's not GWT-compileable
2015-02-16 00:33:32 +01:00
Axel Uhl
559d2d25ed
Merge branch 'master' into bug2589
2015-02-15 17:42:22 +01:00
Axel Uhl
39b1c55a88
made compileable after master mergeMerge branch 'master' into ftes-mail-move-to-sse
...
Conflicts:
java/com.sap.sailing.server/SailingServer (No Proxy).launch
java/com.sap.sailing.server/SailingServer (No Proxy, Cached MTB).launch
java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8889).launch
java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8889, Cached MTB).launch
java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8890).launch
java/com.sap.sailing.server/SailingServer (No Proxy, Remote Debug SAP VM).launch
java/com.sap.sailing.server/SailingServer (No Proxy, winddbTest).launch
java/com.sap.sailing.server/SailingServer (Proxy).launch
java/com.sap.sailing.server/SailingServer (Proxy, Jetty on 8889).launch
java/com.sap.sailing.server/SailingServer (Proxy, Remote Debug SAP VM).launch
java/com.sap.sailing.server/SailingServer (Proxy, SwissTiming Live Simulation).launch
java/com.sap.sailing.server/SailingServer (Proxy, winddbTest).launch
java/com.sap.sse.security.test/META-INF/MANIFEST.MF
java/com.sap.sse.security.test/src/com/sap/sse/security/test/LoginTest.java
java/com.sap.sse.security/src/com/sap/sse/security/impl/Activator.java
java/com.sap.sse.security/src/com/sap/sse/security/impl/SecurityServiceImpl.java
2015-02-14 21:23:24 +01:00
Axel Uhl
f5d87fc908
set bundle context in com.sap.sse.security's Activator.start method right at the beginning
2015-02-13 23:21:20 +01:00
Fredrik Teschke
42e1411bb6
add replication test for mail service (could only test applying changes to master)
2015-02-13 20:30:32 +01:00
Axel Uhl
021b4a96ac
replaced UserRoles.adminitsrator by DefaultRoles.ADMIN
2015-02-13 15:59:24 +01:00
Axel Uhl
d041cece0c
implemented AccessTokenRealm and added a first simple test case
2015-02-13 14:22:33 +01:00
Axel Uhl
dabd2d3a98
fixed initialization of SecurityResourceTest whose first test around access token retrieval is now green
2015-02-13 13:52:05 +01:00
Axel Uhl
0800cab32a
started with access token / REST security; test case read
2015-02-13 11:43:50 +01:00
Axel Uhl
a1a8166b08
fixed MongoDB bundle reference in launch configurations after target platform upgrade
2015-02-13 10:18:32 +01:00
Axel Uhl
ecc6ff8332
Merge branch 'master' into bug2589
2015-02-13 09:31:59 +01:00
Fredrik Teschke
fa887140c8
Merge branch 'master' into ftes-mail-move-to-sse
...
Conflicts:
java/com.sap.sailing.feature/feature.xml
java/com.sap.sailing.server/SailingServer (No Proxy).launch
java/com.sap.sailing.server/SailingServer (Proxy).launch
java/com.sap.sse.security.ui/Security UI sdm.launch
java/pom.xml
2015-02-12 18:14:21 +01:00
Axel Uhl
2269ea3096
starting to implement an access token generator
2015-02-12 17:23:08 +01:00
Fredrik Teschke
f637d50c41
add old jackson bundle as dependency to MANIFESTS to avoid NoClassDefFoundErrors
2015-02-12 13:14:47 +01:00
Fredrik Teschke
c6b68ee17b
move MailException to common bundle (needed by GWT)
2015-02-09 22:36:55 +01:00
Fredrik Teschke
e004c433cc
pull out mail functionality into own service and bundle
...
- needs to live outside com.sap.sse due to dependency on replication
- use mail.properties instead of security.properties
- introduced ServiceTrackerFactory, which led to refactorings in SailingServiceImpl and ~Mock
2015-02-09 21:03:50 +01:00
Axel Uhl
7f7eb10256
move ObjectInputStreamResolvingAgainstCache to com.sap.sse and let com.sap.sse depend on com.sap.sse.common which has the IsManaagedByCache interface
2015-01-14 13:54:45 +01:00
Axel Uhl
24bba04589
moved ObjectInputStreamResolvingAgainstCache to com.sap.sse.common so that com.sap.sailing.domain does not require a dependency on com.sap.sse.replication anymore
2015-01-14 10:59:05 +01:00
Axel Uhl
163e7ca0f6
making the ThreadLocal objectcs instance variables in the Replicables helps the tests that failed due to a lack of isolation between the many Replicable objects in the same VM
2014-12-11 10:06:36 +01:00
Axel Uhl
64451c2702
fixing bug 2493; introduced a ThreadLocal telling whether replica is receiving initial load or running a master operation; not firing back to master if this flag is set
2014-12-11 09:57:18 +01:00
Axel Uhl
b604ff0d37
solving bug 2428 by pulling up the doGetAuthorizationInfo method from UsernamePasswordRealm to AbstractUserStoreBasedReal, thus sharing it with OAuthRealm
2014-12-01 17:54:09 +01:00
Axel Uhl
6a8f4d4c89
added UI support for managing user permissions
2014-12-01 16:56:10 +01:00
Axel Uhl
ebfb80479b
SecurityService is now properly cleared (clearState()) at the beginning of Selenium test case executions
2014-12-01 16:18:58 +01:00
Axel Uhl
30cb8e7082
registering SecurityService as ClearStateTestSupport implementation
2014-12-01 16:01:51 +01:00
Axel Uhl
619a801f3e
solution for bug 2427: permissions are now supported on User and related objects, including persistence and test case
2014-12-01 15:25:47 +01:00
Axel Uhl
8e7ab908e7
replicate operations initiated on replica to master and ignore them when they come back to that replica; see bug 2408
2014-11-29 23:50:06 +01:00
Axel Uhl
47abca3054
solving bug 2480 also for SecurityOperation implementations
2014-11-28 17:34:47 +01:00
Axel Uhl
672ca1b5c8
moved TimerWithRunnable to com.sap.sse and let com.sap.sse.security depend on it, allowing TimerWithRunnable to use Java8 features
2014-11-28 15:03:48 +01:00
Axel Uhl
565c9d9225
made the map storing the sessions scheduled for onChange notifications in a static instead of an instance map
2014-11-26 00:34:01 +01:00
Axel Uhl
b3a0ba280f
delay the sending of change notifications for a Session.touch() event
2014-11-25 21:43:42 +01:00
Axel Uhl
b5b0c61b1c
fixing Shiro session replication by not replacing the caches but replacing the cache contents;
...
Shiro seems to hold long-term references to the caches handed out by the CacheManager. Replacing those
caches during initial load doesn't help. They need to have their *contents* replaced instead.
2014-11-24 23:21:47 +01:00