Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Java EE 5 programmatic authentication

How I can authenticate a user from JSF action (or in servlet doGet/doPost methods)? I mean something like:

Authenticator auth = ...;
if (!auth.authenticate("user","password"))
{
    FacesContext.getInstance().addMessage("Incorrect username or password", null);
}

Restrictions:

  • This method must be compatible with container managed security. (i.e. `HttpServletRequest.getRemoteUser()` must return authenticated user)
  • This method must work everywhere (i.e. on each application server).

Not using j_security_check or another J2EE authentication type (BASIC, DIGEST, etc...)

It is possible?
Or how to create captcha in this way?
Validate that login and password is not empty?
On single page and without JavaScript, of course...

Similar questions... but without answer on this question:

JSF authentication and authorization
Performing user authentication in Java EE / JSF using j_security_check

Edit 1:
I mean serlvet API at least 2.3. Yes, I read about login in Servlet API 3.0, but it is supported only by new versions of application servers.

I think that here can be some solution that implements this authentication for each application server. Sometimes via some hacks, sometimes via special classes designed for this purpose. Like this:

private Class<?> tryClass(String name)
{
    try
    {
        return Class.forName(name);
    }
    catch (ClassNotFoundException e)
    {
        return null;
    }
}

public boolean authenticate(String username, String password) throws AuthenticationException
{
    try
    {

        ExternalContext context = FacesContext.getCurrentInstance().getExternalContext();
        Object request = context.getRequest();
        Object response = context.getResponse();

        Class<?> authClass = tryClass("com.sun.appserv.security.ProgrammaticLogin");
        if (authClass != null)
        {
            return (Boolean)authClass.getMethod("login").invoke(
                authClass.newInstance(), "user", "password", request, response);
        }

        authClass = tryClass("org.jboss.web.tomcat.security.login.WebAuthentication");
        if (authClass != null)
        {
            return (Boolean)authClass.getMethod("login").invoke(
                authClass.newInstance(), "user", "password");
        }

        // ... other hacks ...application servers 

    }
    catch (Exception e)
    {
        throw new AuthenticationException("an error occured during user authentication", e);
    }

    return false;
}
like image 810
ProgramWriter Avatar asked Sep 27 '26 20:09

ProgramWriter


1 Answers

Ah, it's J2EE 1.3 Java EE 5. Too bad, you're out of luck whenever you want to go ahead with container managed security. You have to grab containerspecific implementations from under the covers. By the way, "container managed security without j_security_check or BASIC/DIGEST" is self-contradicting. I would personally just forget about it all and homegrow security or grab a 3rd party implementation which is more configureable, like Spring Security.

like image 123
BalusC Avatar answered Sep 29 '26 10:09

BalusC



Donate For Us

If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!