|
|
|
Экск путей с параметром token из url-pattern засекьюреной web-resource-collection?
|
|||
|---|---|---|---|
|
#18+
может кто подскажет - нужно организовать сквозную аутентификацию - т.е. если приходит в URL параметр token, то по-этому токену запрашиваем у секьюрного сервиса какого юзера это токен и делаем его текущим юзером. всё хорошо, токо веб-фильтр, который это делает, срабатывает только после login-page. соответственно было бы супер указать в web.xml такой url-pattern, который кидал бы на login-page токо если нет параметра token. но проблема в том, что SRV.11.2 Specification of Mappings In the Web application deployment descriptor, the following syntax is used to define mappings: • A string beginning with a‘/’character and ending with a‘/*’suffix is used for path mapping. • A string beginning with a‘*.’prefix is used as an extension mapping. • A string containing only the’/’character indicates the "default" servlet of the application. In this case the servlet path is the request URI minus the con-text path and the path info is null. • All other strings are used for exact matches only. т.е. нельзя написать такой маппинг. ... |
|||
|
:
Нравится:
Не нравится:
|
|||
| 12.10.2012, 20:31:15 |
|
||
|
Экск путей с параметром token из url-pattern засекьюреной web-resource-collection?
|
|||
|---|---|---|---|
|
#18+
На кой вам вообще писать что-то в web.xml resource collection? удалите все - а потом напишите нужный фильтр, замапите потом его на все - а уже внутри фильтра будете смотреть токен. А еще лучше прикрутить spring security ... |
|||
|
:
Нравится:
Не нравится:
|
|||
| 12.10.2012, 21:01:05 |
|
||
|
|

start [/forum/topic.php?fid=59&tid=2130780]: |
0ms |
get settings: |
12ms |
get forum list: |
28ms |
check forum access: |
4ms |
check topic access: |
4ms |
track hit: |
56ms |
get topic data: |
13ms |
get forum data: |
4ms |
get page messages: |
52ms |
get tp. blocked users: |
1ms |
| others: | 340ms |
| total: | 514ms |

| 0 / 0 |
