Win a copy of The Little Book of Impediments (e-book only) this week in the Agile and Other Processes forum!
  • Post Reply
  • Bookmark Topic Watch Topic
  • New Topic

Progammatic Authentication and Declarative Authorization

 
Srivastava Praveen
Greenhorn
Posts: 14
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Can we develop an application where we can use programmatic authentication that means we develop login page and ejb to implement authentication. And declarative authorization that means use deployment descriptor for role information and authorization.

Please suggest.

- Praveen
 
Wirianto Djunaidi
Ranch Hand
Posts: 210
Ruby Ubuntu VI Editor
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
The answer is yes you can. More important question is would you want to?
 
Srivastava Praveen
Greenhorn
Posts: 14
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
I want my login page as requirement may be to use some more information to authenticate the user apart from userid and password. For example, if user fails to login twice, system may ask to provide some information for login. In form based declarative authentication, I can have only userid and password.

I want declarative authentication because currently application is in initial stage and will grow in future to add more roles. So if we have declarative authorization, then code change will not be required.

Please suggest.

- Praveen
 
Ulf Dittmer
Rancher
Posts: 42969
73
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
In my experience, declarative security only works for the most simple uses cases. In all non-trivial applications I've found it much too limiting. It's not realistically possible (or desirable) to differentiate rights and privileges by URL. In many cases, having more (or different) rights means being able to view more (or different) data, not being able to access additional URLs (although that, too, can happen).
 
ray livia
Greenhorn
Posts: 16
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
You could try with JAAS. I did some reading on this. JAAS provide good support on both programmatic custom and container mananged. I did not go very deep into it. Please let me know if any wrong.
 
Farbod H Foomany
Ranch Hand
Posts: 63
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Hi,
Yes what you are saying really makes sense.
You can authenticate for example using biometrics, and fetch the roles from a repository for example, LDAP and you will have the roles with you.
You can authorize as normal then.
 
  • Post Reply
  • Bookmark Topic Watch Topic
  • New Topic