Implement a Tomcat Realm with LDAP authentication and JDBC authorization

后端 未结 2 1095
隐瞒了意图╮
隐瞒了意图╮ 2020-12-15 00:08

I\'m working in a legacy environment where an LDAP server is used only for authentication and contains no roles, and authorization is done against a database which contains

2条回答
  •  暗喜
    暗喜 (楼主)
    2020-12-15 00:59

    You haven't specified the version of Tomcat you're using, so I'm going with 6.x here.

    It looks like you're delegating hasResourcePermission to JDBC while leaving both findSecurityConstraints and hasUserDataPermission in hands of JNDI. You should delegate all of them or none of them.

    Update: JNDIRealm calls protected getRoles(DirContext, User) as part of its authenticate() method. You need to override that and forward it to JDBCRealm's getRoles().

提交回复
热议问题