Win a copy of Java 9 Modularity: Patterns and Practices for Developing Maintainable Applications this week in the Java 9 forum!
  • Post Reply Bookmark Topic Watch Topic
  • New Topic

User impersonation using Filters/Cookies  RSS feed

Brian Quinn
Ranch Hand
Posts: 32
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Building an application in Flex/Java that requires a super user to be able to impersonate another user. We did this by having a spring controller write a cookie with target user's id. Then app reloads. A filter is on the app that looks for cookie and build a principal off that user id if it finds the cookie, or it builds a prinicipal based on Cleartrust headers. It then sticks Principal on session and in a thread local so java service layer can find it. However we are seeing that as the app reloads, it starts with the intended impersonated user id, but then it changes over to the super user's id. I was wondering if there were some ideas better than the cookie/filter way to maybe implement this feature.
  • Post Reply Bookmark Topic Watch Topic
  • New Topic
Boost this thread!