[main] credentialsMatcher = org.apache.shiro.authc.credential.Sha256CredentialsMatcher credentialsMatcher.storedCredentialsHexEncoded = false credentialsMatcher.hashIterations = 1024 # Realm configuration: # -------------------- # Uncomment the following line to specify a bundle-specific permissions-for-role provider # permissionsForRoleProvider = com.sap.myapp....MyAppPermissionsForRoleProvider upRealm = com.sap.sse.security.UsernamePasswordRealm upRealm.credentialsMatcher = $credentialsMatcher # Uncomment the following line make the upRealm aware of the permissionsForRoleProvider # upRealm.permissionsForRoleProvider = $permissionsForRoleProvider oauthRealm = com.sap.sse.security.OAuthRealm # Uncomment the following line make the oauthRealm aware of the permissionsForRoleProvider # oauthRealm.permissionsForRoleProvider = $permissionsForRoleProvider bearerTokenRealm = com.sap.sse.security.BearerTokenRealm # Uncomment the following line make the bearerTokenRealm aware of the permissionsForRoleProvider # bearerTokenRealm.permissionsForRoleProvider = $permissionsForRoleProvider # Putting it all together: sessionManager = com.sap.sse.security.SecurityWebSessionManager securityManager.sessionManager = $sessionManager sessionDAO = org.apache.shiro.session.mgt.eis.EnterpriseCacheSessionDAO securityManager.sessionManager.sessionDAO = $sessionDAO cacheManager = com.sap.sse.security.SessionCacheManager securityManager.cacheManager = $cacheManager # Authentication Filter Configurations # ------------------------------------ # A filter that requires the user to have at least one of the roles specified as # filter parameter. This makes it different from the default roles[...] filter # which requires the user to have ALL of the roles specified as parameters. anyofroles = com.sap.sse.security.AnyOfRolesFilter # A custom filter for GWT pages that require an authenticated user. # Forwards unauthenticated users to the default login page. When # addressed directly (and not based on a redirect), users who logged # on successfully will be redirected to the UserManagement.html page # where they can adjust their profile. customGwt = com.sap.sse.security.CustomFilter customGwt.loginUrl = /security/ui/Login.html customGwt.successUrl = /UserManagement.html # Configuration for the default shiro HTTP form authentication filter. # It assumes that form-based login parameters are sent to the # /api/restsecurity/login RESTlet and forwards successful login attempts # to the /api/restsecurity/hello service which is expected to respond # with a JSON document containing the authenticated subject's properties. authc.loginUrl = /api/restsecurity/login authc.successUrl = /api/restsecurity/hello # This authentication filter accepts a bearer access token in the HTTP # Authorization header field, as in # Authorization: Bearer 1029741026501365024376093245 # If no such bearer token is provided, the filter falls back to basic HTTP # authentication ("Authentication: Basic ...") and then regular form-based # authentication with POST parameters "username" and "password". bearerToken = com.sap.sse.security.BearerTokenOrBasicOrFormAuthenticationFilter # Specifying filter chains for URL patterns [urls] /api/restsecurity/login = authc /api/restsecurity/logout = logout /api/restsecurity/access_token = bearerToken /api/restsecurity/remove_access_token = bearerToken /api/restsecurity/hello = bearerToken