Java EE 6 Programmatic security, glassfish and JDBC realm

前端 未结 2 611
名媛妹妹
名媛妹妹 2021-01-14 18:05

I\'m exploring pure Java EE ways of doing programmatic security, especially login users, based on the jdbc realm from my glassfish server.

So basically, in my login

2条回答
  •  不要未来只要你来
    2021-01-14 18:47

    Well, there are two aspects to security in web applications : Authentication and Authorization. What you are using here is programmatic authentication (the way users are logging in) and declarative authorization (defining what users are allowed to see). There is no issue in mixing both, in my opinion.

    If you keep your realm in your web.xml, your application will be more portable. (meaning you can deploy your war in e.g. a tomcat server without changes).

提交回复
热议问题