This week's book giveaway is in the Design forum.
We're giving away four copies of Building Microservices and have Sam Newman on-line!
See this thread for details.
The moose likes Security and the fly likes Problem with security constraint Big Moose Saloon
  Search | Java FAQ | Recent Topics | Flagged Topics | Hot Topics | Zero Replies
Register / Login

Win a copy of Building Microservices this week in the Design forum!
JavaRanch » Java Forums » Engineering » Security
Bookmark "Problem with security constraint" Watch "Problem with security constraint" New topic

Problem with security constraint

DeAlton Jones

Joined: Apr 04, 2006
Posts: 22
Hi Everyone,

I am trying to secure a particular web page in my project by using security constraint in my web.xml. I am authenticating against a LDAP Server and am successful in getting the roles for the particular user.

Most of the pages will be seen to anyone who successfully logs in but a few of the pages I want only people with an admin or super super role to see it.

so this is what i put in my web xml

While this seems to be correct the user still has access to the page the constraint then works when they try to use the page ex.(click on a submit button, or link on the page) then the browser displays no authorization page.

Is there anyway to get this working so that when the user gets stopped before they get to the page. I am successful on rendering links based on the roles returned but I want to prevent them from typing in the url to get to the resource.

Thanks in advance for you help

DeAlton Jones

Joined: Apr 04, 2006
Posts: 22
I figured it out. xml is read from the top down I had a public constraint that overrided the protected constraint in the wrong order
I’ve looked at a lot of different solutions, and in my humble opinion Aspose is the way to go. Here’s the link:
subject: Problem with security constraint
It's not a secret anymore!