File APIs for Java Developers
Manipulate DOC, XLS, PPT, PDF and many others from your application.
http://aspose.com/file-tools
The moose likes Spring and the fly likes How to implement Spring Form Based Authenticationand Authorization without session scope ? Big Moose Saloon
  Search | Java FAQ | Recent Topics | Flagged Topics | Hot Topics | Zero Replies
Register / Login
JavaRanch » Java Forums » Frameworks » Spring
Bookmark "How to implement Spring Form Based Authenticationand Authorization without session scope ? " Watch "How to implement Spring Form Based Authenticationand Authorization without session scope ? " New topic
Author

How to implement Spring Form Based Authenticationand Authorization without session scope ?

kumar shinde
Ranch Hand

Joined: Oct 17, 2005
Posts: 36

Hello Ranchers ,

We are working on a web based application using Springs .
This application will be handling request using load balancing servers .
Due to some issues in load balancing servers for request , the client does not want to use anything in Springs kept in session scope or Application Context scope.

Now we are trying to use Form Based Authentication and Authorization in springs .
But looking out the examples based on spring authentication it seems that spring security context executes in session scope
We want to implement form based authentication in springs without a session scope .



The sample code in security file (Security using database) will be something like this :-



Hence, I want to know, is there any way to implement spring form base authentication and authorization without session scope ... maybe request scope or cookies ?

Any pointer or help in this regard will be very helpful as this is now major blocker for our app

Thanks in Advance
Vyas Sanzgiri
Ranch Hand

Joined: Jun 16, 2007
Posts: 686

wait a minute..so your load balancer config is such that user can flip flop between load balancers at every hit? In that case, how do load balancers sync with each other? Do you want to send the cookie around every time?

In our case, once user sticks to one load balancer he is served until there is no session left for that user. He does not switch from one to another.

Cookies and request scope is the only other way I see this working but I feel that is overkill for your app...unless it is high security tool


===Vyas Sanzgiri===
My Blog
kumar shinde
Ranch Hand

Joined: Oct 17, 2005
Posts: 36
Yes exactly Vyas !!!

Each time a request comes it may or may not flip flop between load balancer's , hence we cannot use session .

I know that cookies or request will be overkill, but this is how the client wants .

Hence I want to know how can spring based authentication and authorization as mentioned previously can be implemented using cookies or request .




 
I agree. Here's the link: http://aspose.com/file-tools
 
subject: How to implement Spring Form Based Authenticationand Authorization without session scope ?
 
Similar Threads
A better way to display a login failure message
Error: The matching wildcard is strict, but no declaration can be found for element 'remember-me'
Spring Security 2.0.4 .... Redirect user to original page after authentication success or failure
RichFaces + Spring Security -- Problem Load RichFaces
spring security form based login using database not responding