Commit Graph
171 Commits
Author SHA1 Message Date
Axel Uhl 32daae4ad3 where concurrency support plays a role, changed field declarations from ConcurrentHashMap to ConcurrentMap which is sufficiently specific
Change-Id: I71254d96d495a1a8d79e009d70fd8928b720b31e
2016-06-07 17:08:07 +02:00
Axel Uhl 913fbe5d76 increased Shiro session manager timeout from 30min to 24h
Change-Id: I8bdcbc5b3c2658858643b3a4f04dfa83a571659a
2016-04-20 18:00:19 +02:00
Axel Uhl 3d25d4537d use a dedicated authentication filter that provides an application name so the HTTP response's WWW-Authentication header shows it
Change-Id: I81f43969acb0aeada3bdb5b6f066c62aa00d0de6
2016-03-08 21:47:53 +01:00
Axel Uhl 2bae2dc265 fixed token generation for QR code; required getOrCreateAccessToken instead of only getAccessToken
Change-Id: Id7817e8f2c7939b088689acb3ac9b9ae42638643
2016-03-03 15:15:04 +01:00
Axel Uhl 44c37b4c32 fixed SecurityResourceTest, now removing existing token when requiring creation of new one
Change-Id: I1e8a5be5f7659ba0bff2841bed02033139de1b8a
2016-03-02 10:59:54 +01:00
Axel Uhl 524abc1124 secure the RaceLog POST servlet, requiring LEADERBOARD.UPDATE; fixed auth token loading in UserStore;
added removeAccessToken with remove_access_token end point on SecurityResource, available for ADMIN role
and owner
2016-03-02 00:09:54 +01:00
Axel Uhl c356c2f97c Merge branch 'master' into bug2589
Conflicts:
	java/com.sap.sailing.domain.common/src/com/sap/sailing/domain/common/security/Permission.java
	java/com.sap.sailing.domain.common/src/com/sap/sailing/domain/common/security/SailingPermissionsForRoleProvider.java

Change-Id: I3aaf2651c01460dd2fb0caf95735b9919586a2c9
2016-03-01 16:47:00 +01:00
Benjamin Barth 842d64d5e5 Added parameters full name and company to
UserManagementService.createSimpleUser method
2016-01-21 16:28:04 +01:00
Axel Uhl 432c979135 Merge branch 'master' into bug2589
Conflicts:
	java/com.sap.sailing.server.gateway/src/com/sap/sailing/server/gateway/jaxrs/api/EventsResource.java

Change-Id: I63f05a28bdf63a0c6b7731e03c36b28b61e4638e
2016-01-12 14:28:13 +01:00
Axel Uhl f91153d93c cleaned up the ClientUtils implementation and removed unused OAuth cruft; removed GWT dependency from com.sap.sse.security;
removed RemoteServiceServlet superclass from SecurityServiceImpl; why was it there? The GWT RPC is implemented by
UserManagementServiceImpl

Change-Id: Ifc2e1f848b9fb5d7f24398a0497d301b037a822e
2016-01-12 09:43:07 +01:00
Axel Uhl 4e0c3f7073 providing update feature for additional User properties in SecurityService and UserManagementService
Change-Id: I46a4c2c58e35595dc20b85575a27c1cfbd639592
2016-01-12 09:28:23 +01:00
Axel Uhl fb3f74d297 added fields fullName and company to User
Change-Id: I831b2a229c29081aab8f79174caa8d1900303b67
2016-01-12 09:13:01 +01:00
Axel Uhl 8246a64a3f using UriUtils.fromString to avoid XSS security vulnerability
Change-Id: Ia6aada15502dd1e4e6a53cf9e6067fbea6a07fef
2016-01-08 11:01:54 +01:00
Axel Uhl 6169f54e25 Merge branch 'master' into bug2589
Conflicts:
	java/com.sap.sailing.domain.igtimiadapter/META-INF/MANIFEST.MF
	java/com.sap.sailing.gwt.ui/src/main/java/com/sap/sailing/gwt/ui/server/SailingServiceImpl.java
	java/com.sap.sailing.server.gateway/META-INF/MANIFEST.MF
	java/com.sap.sailing.server.gateway/src/com/sap/sailing/server/gateway/jaxrs/RestServletContainer.java
	java/com.sap.sailing.server.gateway/src/com/sap/sailing/server/gateway/jaxrs/api/RestApiApplication.java

Change-Id: I8cbb797ba64d221ea401b90b22d21a813204a6f2
2016-01-04 11:34:01 +01:00
Axel Uhl 374bad01d8 use SecureRandom for user e-mail validation token generation 2015-12-08 12:46:56 +01:00
Frederik Petersen 883ef38d90 Now logging when tracked race is connected with race column
also loggin which user linked the race.
2015-07-21 15:47:20 +02:00
Axel Uhl a9f43bf2f3 fixing bug 2849 by fixing the mismatch of username vs. e-mail address parameter semantics for MailService.sendMail 2015-05-12 22:19:31 +02:00
Axel Uhl 041b50cc3d introduced Jersey ExceptionMapper for Shiro's AuthorizationException 2015-02-26 17:26:45 +01:00
Axel Uhl 6bd56de7f1 cleaned up shiro.ini stuff further, added more comments 2015-02-26 13:48:51 +01:00
Axel Uhl 1cc22d3858 added anyofroles filter declaration to default shiro.ini 2015-02-26 12:42:47 +01:00
Axel Uhl bd327fe876 added comments and cleaned up structure in com.sap.sse.security/resources/shiro.ini to make it a good copy template, too 2015-02-26 12:35:59 +01:00
Axel Uhl c196f48ad1 prepared the com.sap.sailing.server.gateway bundle for REST security, showing a commented example in shiro.ini for the /events service end point 2015-02-25 18:26:27 +01:00
Axel Uhl 6c5b4e9027 added documentation for the security REST API 2015-02-25 17:22:23 +01:00
Axel Uhl 21f76c6dc4 obsolete old bearer access token when a new one is obtained for the subject 2015-02-25 14:36:01 +01:00
Axel Uhl 837fce4a6c re-use subject instead of acquiring it freshly where possible 2015-02-25 12:32:01 +01:00
Axel Uhl 6ad8d92981 don't save the username in the SOCIAL_USER field; it can always be obtained by Subject.getPrincipal() 2015-02-25 12:28:23 +01:00
Axel Uhl ae9ca81f45 fixed launch configs regarding zxing bundle; added Javadoc 2015-02-25 09:37:41 +01:00
Axel Uhl 8d76c78c48 added missing class FormAuthenticationFilterWithPublicCreateToken which is a delegate for the bearer token authentication filter 2015-02-25 08:38:53 +01:00
Axel Uhl 6076f03c60 enhanced logon procedures and fixed test cases 2015-02-25 00:53:43 +01:00
Axel Uhl cf010e8c02 provide and use a BearerTokenAuthenticationFilter which defaults to HTTP basic authentication; renamed AccessTokenRealm to BearerTokenRealm 2015-02-24 21:58:02 +01:00
Axel Uhl 695ebe0be9 fixed media types for SecurityResource 2015-02-24 15:34:58 +01:00
Axel Uhl e70e605f79 Merge branch 'master' into bug2589 2015-02-23 18:25:45 +01:00
Axel Uhl 8762002794 made all gwt.osgi to gwt.dev dependencies optional 2015-02-23 18:25:11 +01:00
Axel Uhl a964dcda47 require authenticated user to create UserDTO 2015-02-17 18:12:00 +01:00
Axel Uhl 73f7ce197f whitespace changes only 2015-02-16 23:40:05 +01:00
Axel Uhl ef698c16a0 removed cherry-picked effects of permission management 2015-02-16 15:59:55 +01:00
Axel Uhl eaacd3f4c1 moved server-side QR code stuff from sse.common to sse because it's not GWT-compileable
Conflicts:
	java/com.sap.sailing.gwt.ui/src/main/java/com/sap/sailing/gwt/ui/client/shared/security/SailingPermissionsForRoleProvider.java
	java/com.sap.sse.security.common/src/com/sap/sse/security/shared/PermissionsForRoleProvider.java
	java/com.sap.sse.security/src/com/sap/sse/security/AbstractUserStoreBasedRealm.java
2015-02-16 15:58:18 +01:00
Axel Uhl 26b55ffd32 moved server-side QR code stuff from sse.common to sse because it's not GWT-compileable 2015-02-16 00:33:32 +01:00
Axel Uhl 559d2d25ed Merge branch 'master' into bug2589 2015-02-15 17:42:22 +01:00
Axel Uhl 39b1c55a88 made compileable after master mergeMerge branch 'master' into ftes-mail-move-to-sse
Conflicts:
	java/com.sap.sailing.server/SailingServer (No Proxy).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, Cached MTB).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8889).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8889, Cached MTB).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, Jetty on 8890).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, Remote Debug SAP VM).launch
	java/com.sap.sailing.server/SailingServer (No Proxy, winddbTest).launch
	java/com.sap.sailing.server/SailingServer (Proxy).launch
	java/com.sap.sailing.server/SailingServer (Proxy, Jetty on 8889).launch
	java/com.sap.sailing.server/SailingServer (Proxy, Remote Debug SAP VM).launch
	java/com.sap.sailing.server/SailingServer (Proxy, SwissTiming Live Simulation).launch
	java/com.sap.sailing.server/SailingServer (Proxy, winddbTest).launch
	java/com.sap.sse.security.test/META-INF/MANIFEST.MF
	java/com.sap.sse.security.test/src/com/sap/sse/security/test/LoginTest.java
	java/com.sap.sse.security/src/com/sap/sse/security/impl/Activator.java
	java/com.sap.sse.security/src/com/sap/sse/security/impl/SecurityServiceImpl.java
2015-02-14 21:23:24 +01:00
Axel Uhl f5d87fc908 set bundle context in com.sap.sse.security's Activator.start method right at the beginning 2015-02-13 23:21:20 +01:00
Fredrik Teschke 42e1411bb6 add replication test for mail service (could only test applying changes to master) 2015-02-13 20:30:32 +01:00
Axel Uhl 021b4a96ac replaced UserRoles.adminitsrator by DefaultRoles.ADMIN 2015-02-13 15:59:24 +01:00
Axel Uhl d041cece0c implemented AccessTokenRealm and added a first simple test case 2015-02-13 14:22:33 +01:00
Axel Uhl dabd2d3a98 fixed initialization of SecurityResourceTest whose first test around access token retrieval is now green 2015-02-13 13:52:05 +01:00
Axel Uhl 0800cab32a started with access token / REST security; test case read 2015-02-13 11:43:50 +01:00
Axel Uhl a1a8166b08 fixed MongoDB bundle reference in launch configurations after target platform upgrade 2015-02-13 10:18:32 +01:00
Axel Uhl ecc6ff8332 Merge branch 'master' into bug2589 2015-02-13 09:31:59 +01:00
Fredrik Teschke fa887140c8 Merge branch 'master' into ftes-mail-move-to-sse
Conflicts:
	java/com.sap.sailing.feature/feature.xml
	java/com.sap.sailing.server/SailingServer (No Proxy).launch
	java/com.sap.sailing.server/SailingServer (Proxy).launch
	java/com.sap.sse.security.ui/Security UI sdm.launch
	java/pom.xml
2015-02-12 18:14:21 +01:00
Axel Uhl 2269ea3096 starting to implement an access token generator 2015-02-12 17:23:08 +01:00