Web Security Tutorial Update

Dan Kolar <[email protected]> Mon, 14 Aug 2006 14:39:29 +0200
Newsgroups gmane.comp.java.netbeans.webteam
Message-ID <[email protected]>
Hi Ken,

 I send you updated tutorial, hope it will be ok now.
I guess we should mention in somehow also valuable comment from Grover 
Blue <[email protected]>.
Thanks

Dan
Securing a Web Application in NetBeans IDE 5.5.html (text/html, 41.3 KB)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  <meta http-equiv="Content-Language" content="en-us">
  <script
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/tigris00.js"
 type="text/javascript"></script>
  <link rel="stylesheet" type="text/css"
 href="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/netbeans.css">
  <meta http-equiv="Content-Style-Type" content="text/css">
  <meta http-equiv="Content-Style-Type" content="text/css">
  <meta name="SourceCastVersion" content="3.5.1.19.7">
  <meta name="keywords"
 content="NetBeans, IDE, Platform, free, open source, developer">
  <meta name="SourceCastVersion" content="2.6.2.4.10">
  <meta name="keywords"
 content="NetBeans, IDE, Platform, free, open source, developer">
  <meta name="description" content="">
  <meta name="author" content="Dan Kolar">
  <meta name="GENERATOR" content="Microsoft FrontPage 4.0">
  <meta name="ProgId" content="FrontPage.Editor.Document">
  <title>Securing a Web Application in NetBeans IDE 5.5</title>
  <link rel="shortcut icon"
 href="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/favicon0.ico"
 type="image/x-icon">
  <link rel="shortcut icon"
 href="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/favicon0.ico"
 type="image/x-icon">
  <style type="text/css">
            <!--
.java-block-comment {color: #737373}
.java-string-literal {color: #99006b}
.java-layer-method {font-family: Monospaced; font-weight: bold}
.java-keywords {color: #000099; font-family: Monospaced; font-weight: bold}
.html-tag {color: #0000ff}
.html-sgml-declaration {color: #bf9221}
.xml-attribute {color: #007c00}
.xml-pi-start {color: #00007c; font-family: Monospaced; font-weight: bold}
.xml-tag {color: #0000ff}
.xml-value {color: #99006b}
.xml-pi-content {color: #00007c}
.jsp-html-argument {color: #007c00}
.jsp-jsptag-whitespace {background-color: #eff0eb; font-family: Monospaced; font-weight: bold}
.jsp-jsptag-comment {color: #808080; font-family: Monospaced; font-weight: bold}
.jsp-jsptag-attribute-name {color: #007c00; background-color: #eff0eb}
.jsp-html-tag {color: #0000ff}
.jsp-html-sgml-declaration {color: #bf9221}
.jsp-xml-value {color: #99006b}
.jsp-jsptag-attribute-value {color: #99006b; background-color: #eff0eb}
.jsp-jsptag-tag-directive {color: #0000ff; background-color: #eff0eb; font-family: Monospaced; font-weight: bold}
body {color: #000000; background-color: #ffffff; font-family: Monospaced}
table {color: #000000; background-color: #e9e8e2; font-family: Monospaced}
.sql-identifier {color: #0000ff}
.sql-string-literal {color: #99006b}
.sql-keyword {color: #000099; font-family: Monospaced; font-weight: bold}
.sql-int-literal {color: #780000}
-->

            -->
        </style>
  <link rel="stylesheet" type="text/css"
 href="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/netbeans.css"
 media="screen">
  <script
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/lang-pul.js"
 type="text/javascript"></script>
  <script language="JavaScript" type="text/javascript">
<!--
function get_sc_login() {
  var sclogin = "dkolar";
  if(sclogin.indexOf("()")==-1) {
  	 return (sclogin);
  } else {
  	 return "guest";
  }

}
var username=get_sc_login();
//-->
  </script>
</head>
<body onload="loginfocus()" class="composite">
<!-- begin TopTabs --><!-- end TopTabs --><!-- start NavCol --><!-- end NavCol --><!-- Servlet-Specific template -->
<table border="0" cellspacing="0" cellpadding="0" width="100%">
  <tbody>
    <tr>
      <td colspan="2" nowrap="nowrap">
      <div id="topcheat"><img
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/nic00000.gif"
 alt="" width="760" height="1" border="0"></div>
      <div id="inheader">
      <div id="logo"><a title="Home"
 href="http://www.netbeans.org/index.html"><img
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/netbeans.gif"
 alt="NetBeans logo " title="NetBeans logo " width="179" height="65"
 border="0" class="iLogo"></a></div>
<!-- Tab Navigation -->
      <div id="menu"><a
 href="http://www.netbeans.org/downloads/index.html" title="Downloads"><img
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/download.gif"
 alt="Downloads" width="81" height="59" border="0" class="iMenu"><span>Downloads</span></a><a
 href="http://www.netbeans.org/products/index.html" title="Products"><img
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/products.gif"
 alt="Products" width="68" height="59" border="0" class="iMenu"><span>Products</span></a><a
 href="http://www.netbeans.org/catalogue/index.html" title="Plugins"><img
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/catalogu.gif"
 alt="Plugins" width="62" height="59" border="0" class="iMenu"><span>Plugins</span></a><a
 href="http://www.netbeans.org/kb/50/index.html" title="Docs&nbsp;&amp;&nbsp;Support"><img
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/kb-on000.gif"
 alt="Docs&nbsp;&amp;&nbsp;Support" width="108" height="59" border="0" class="iMenu"><span>Docs&nbsp;&amp;&nbsp;Support</span></a><a
 href="http://www.netbeans.org/community/index.html" title="Community"><img
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/communit.gif"
 alt="Community" width="84" height="59" border="0" class="iMenu"><span>Community</span></a><a
 href="http://www.netbeans.org/community/partners/index.html"
 title="Partners"><img
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/partners.gif"
 alt="Partners" width="70" height="57" border="0" class="iMenu"><span>Partners</span></a><a
 href="http://www.netbeans.org/about/index.html" title="About"><img
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/about000.gif"
 alt="About" width="55" height="59" border="0" class="iMenu"><span>About</span></a><a
 href="http://www.netbeans.org/switch/index.html" title="Switch"><img
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/switch00.gif"
 alt="Switch" width="60" height="57" border="0" class="iMenu"><span>Switch</span></a></div>
      </div>
      <div id="print"><a href="#"
 onclick='window.open("http://testwww.netbeans.org/kb/articles/security-webapps.html","","width=600,left=0,top=0,scrollbars=yes,resizable=yes,toolbar=yes,location=yes,menubar=yes");'><img
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/print000.gif"
 alt="" width="105" height="15" border="0"></a></div>
      </td>
    </tr>
    <tr>
      <td valign="top">
      <div id="content">
      <div id="innav"><a href="http://www.netbeans.org/index.html">HOME</a>
&gt; <a href="http://www.netbeans.org/kb/index.html">Docs &amp; Support</a></div>
      <table border="0" cellspacing="0" cellpadding="0">
        <tbody>
          <tr>
            <td valign="top">
            <div id="leftmenu"><!-- Left Navigation -->
            <div class="leftnavtitle">Docs&nbsp;&amp;&nbsp;Support</div>
            <div class="leftmenuplus">
            <div class="leftmenuitem"><a
 href="http://www.netbeans.org/kb/55/">NetBeans IDE 5.5</a></div>
            </div>
            <div class="leftmenuplus">
            <div class="leftmenuitem"><a
 href="http://www.netbeans.org/kb/50/">NetBeans IDE 5.0</a></div>
            </div>
            <div class="leftmenuplus">
            <div class="leftmenuitem"><a
 href="http://www.netbeans.org/kb/41/">NetBeans IDE 4.1</a></div>
            </div>
            <div class="leftmenuplus">
            <div class="leftmenuitem"><a
 href="http://www.netbeans.org/kb/archive/">Older Releases</a></div>
            </div>
            <div class="leftmenuplus">
            <div class="leftmenuitem"><a
 href="http://www.netbeans.org/kb/faqs/">User FAQs</a></div>
            </div>
            <div class="leftmenug">
            <div class="leftmenuitem"><a
 href="http://www.netbeans.org/kb/kb.html">Articles</a></div>
            </div>
            <div class="leftmenug">
            <div class="leftmenuitem"><a
 href="http://www.netbeans.org/kb/50/flash.html">Flash Demos</a></div>
            </div>
            <div class="leftmenug">
            <div class="leftmenuitem"><a
 href="http://www.netbeans.org/kb/articles/books.html">Books</a></div>
            </div>
            <div class="leftmenug">
            <div class="leftmenuitem"><a
 href="http://www.netbeans.org/kb/articles/learn-java.html">Learning
Java</a></div>
            </div>
            <div class="leftmenug">
            <div class="leftmenuitem"><a
 href="http://platform.netbeans.org/index.html">Module Developer's
Resources</a></div>
            </div>
            <div class="leftmenug">
            <div class="leftmenuitem"><a
 href="http://developers.sun.com/developer_help/">NetBeans Support</a></div>
            </div>
            <br>
            <br>
            <br>
            </div>
            </td>
            <td width="100%" valign="top">
            <div id="contentLeft"><!-- Begin Content Area -->
            <h1>Securing a Web Application in NetBeans IDE 5.5</h1>
            <div class="articledate" style="margin-left: 0px;">Contributed
and maintained by Dan Kolar</div>
            <p>This document takes you through the basics of adding
security to a web application that is deployed to
either the Tomcat server or the Sun Java System Application Server.</p>
            <p>This document shows you how to configure security
authentication using a basic login window and also using a login form
in a web page.
This document takes you through the steps for creating users on the
Tomcat server and Sun Java System Application Server.
After creating the users, you then create the security roles by setting
the security properties in the deployment descriptor.
This document also shows how you can use JDBC authentication to secure
your application when deploying to the Sun Java System Application
Server.</p>
            <div class="indent">
            <h3 class="tutorial">Software Needed</h3>
            <p>Before you begin, you need to install the following
software on your computer:</p>
            <ul>
              <li>NetBeans IDE 5.5 (development build) (<a
 href="http://www.netbeans.info/downloads/download.php?a=n&amp;p=1">download</a>).</li>
              <li>Java Standard Development Kit (JDK) version 5.0 (<a
 href="http://java.sun.com/Java%20SE/1.5.0/download.jsp">download</a>).</li>
              <li>(optional) Sun Java System Application Server 9.0 (<a
 href="https://glassfish.dev.java.net/public/downloadsindex.html">download</a>).</li>
            </ul>
            <h3 class="tutorial">Notations Used in the Tutorial</h3>
            <p><i>&lt;NETBEANS_HOME&gt;</i> - NetBeans IDE installation
directory<br>
            <i>&lt;APPSERVER_HOME&gt;</i> - Sun Java System Application
Server installation directory<br>
            <i>&lt;TOMCAT_HOME&gt;</i> - Tomcat installation directory<br>
            <i>&lt;PROJECT_HOME&gt;</i> - directory containing your
project</p>
            <h3 class="tutorial">Securing a Web Application in NetBeans
IDE 5.5</h3>
            <p>In this document you will go through the following steps:</p>
            <ul>
              <li><a href="#Exercise_0">Installing and Configuring the
Working Environment</a></li>
              <li><a href="#Creating_Web_App">Creating the Web
Application</a>
                <ul>
                  <li><a href="#createdir">Creating the Secure
Directories</a></li>
                  <li><a href="#indexpage">Creating the JSP Index Page</a></li>
                  <li><a href="#loginform">Creating a Login Form
(optional)</a></li>
                </ul>
              </li>
              <li><a href="#Creating_users_roles">Creating Users and
Roles on the Target Server</a>
                <ul>
                  <li><a href="#Tomcat">Defining Roles on Tomcat Web
Server</a></li>
                  <li><a href="#SJSAS">Defining Roles on Sun Java
System Application Server</a></li>
                </ul>
              </li>
              <li><a href="#Basic_login_config">Configuring the Login
Method</a>
                <ul>
                  <li><a href="#Basic">Basic Login</a></li>
                  <li><a href="#Form">Form Login</a></li>
                </ul>
              </li>
              <li><a href="#jdbc">Using JDBC Authorization</a></li>
              <li><a href="#Deploy_run">Deploying and Running the
Application</a></li>
            </ul>
            </div>
<!-- ===================================================================================== -->
            <h2><a name="Exercise_0"></a>Installing and Configuring the
Working Environment</h2>
            <p>Install and start NetBeans IDE 5.5.
You can do this tutorial using the bundled Tomcat server or using the
Sun Java
System Application Server 9.0, Platform Edition.</p>
            <p>If you are using the Sun Java System Application Server,
make sure the server is installed and a server instance is registered
with the IDE. You can use the Server Manager to register the server
instance.
(Choose Tools &gt; Server Manager &gt; Add Server. Select "Sun Java
System Application Server" &gt; and click Next. Click Browse and locate
the installation
directory of the application server. Click Finish.)</p>
<!-- ===================================================================================== -->
            <h2 class="tutorial"><a name="Creating_Web_App"></a><!--Exercise 1: -->Creating
the Web Application</h2>
            <p>In this excercise you first create the web application
project and the directory structure. You then create some simple <tt>html</tt>
files in each of the secure directories.
The web application uses a basic login authentication for accessing the
secure directories. If you want to use a login form for authentication,
you can add a <tt>jsp</tt> page with the form.</p>
            <div class="indent"> <a name="createdir"></a>
            <h3 class="tutorial">Creating the Secure Directories</h3>
            <ol>
              <li>Choose File &gt; New Project (Ctrl-Shift-N), select
Web
Application from the Web category, and click Next.</li>
              <li>Name the project WebApplicationSecurity, choose the
server you want to use and click Finish.</li>
              <li>In the Projects window of the IDE, right-click Web
Pages and choose New &gt; Folder.</li>
              <li>In the New Folder wizard, name the folder secureAdmin
and click Finish.</li>
              <li>Repeat steps 3 and 4 to create another folder named
secureUser.</li>
              <li>Create a new <tt>html</tt> by right-clicking the
folder secureUser and choosing New &gt; HTML.</li>
              <li>Name the new file pageU and click Finish. When you
click Finish, the file <tt>pageU.html</tt> opens in the Source Editor.</li>
              <li>In the Source Editor, add the following content to <tt>pageU.html</tt>.
                <pre class="examplecode"><span class="html-tag">&lt;html&gt;<br>   &lt;head&gt;<br>      &lt;title&gt;</span>User secure area<span
 class="html-tag">&lt;/title&gt;<br>   &lt;/head&gt;<br>   &lt;body&gt;<br>      &lt;h1&gt;</span>User Secure Area<span
 class="html-tag">&lt;/h1&gt;<br>   &lt;/body&gt;<br>&lt;/html&gt;</span></pre>
              </li>
              <li>Right-click the secureAdmin folder and create a new <tt>html</tt>
file named pageA.</li>
              <li>In the Source Editor, add the following to <tt>pageA.html</tt>
                <pre class="examplecode"><span class="html-tag">&lt;html&gt;<br>   &lt;head&gt;<br>      &lt;title&gt;</span>Admin secure area<span
 class="html-tag">&lt;/title&gt;<br>   &lt;/head&gt;<br>   &lt;body&gt;<br>      &lt;h1&gt;</span>Admin secure area<span
 class="html-tag">&lt;/h1&gt;<br>   &lt;/body&gt;<br>&lt;/html&gt;</span></pre>
              </li>
            </ol>
            <a name="indexpage"></a>
            <h3 class="tutorial">Creating the JSP Index Page</h3>
            <p>You now create the JSP index page containing links to
the secure areas. When the user clicks on the link they are prompted
for the username and password. If you use a basic login, they are
prompted by the default browser login window.
If you use a login form page, the the user enters the username and
password in a form.</p>
            <ol>
              <li>Open <tt>index.jsp</tt> in the Source Editor and add
the following links to <tt>pageA.html</tt> and <tt>pageU.html</tt>:
                <pre class="examplecode"><span class="jsp-html-tag">&lt;p&gt;</span>Request a secure Admin page <span
 class="jsp-html-tag">&lt;a</span> <span class="jsp-html-argument">href=</span><span
 class="jsp-xml-value">"secureAdmin/pageA.html"</span><span
 class="jsp-html-tag">&gt;</span>here!<span class="jsp-html-tag">&lt;/a&gt;&lt;/p&gt;<br>&lt;p&gt;</span>Request a secure User page <span
 class="jsp-html-tag">&lt;a</span> <span class="jsp-html-argument">href=</span><span
 class="jsp-xml-value">"secureUser/pageU.html"</span> <span
 class="jsp-html-tag">&gt;</span>here!<span class="jsp-html-tag">&lt;/a&gt;&lt;/p&gt;</span></pre>
              </li>
            </ol>
            <a name="loginform"></a>
            <h3 class="tutorial">Creating a Login Form (optional)</h3>
            <p>If you want to use a login form instead of the basic
login, you can create a <tt>jsp</tt> page containing the form. You
then specify the login and error pages when <a
 href="#Basic_login_config">configuring the login method</a>.</p>
            <ol>
              <li>In the Projects window, right-click the folder Web
Pages and choose New &gt; JSP.</li>
              <li>Name the file <tt>login</tt>, leave the other fields
at their default value and click Finish.</li>
              <li>In the Source Editor, add the following code to <tt>login.jsp</tt>
and then save and close the file.<br>
                <pre class="examplecode"><span
 class="jsp-jsptag-whitespace">&lt;%@</span><span
 class="jsp-jsptag-tag-directive">taglib</span> <span
 class="jsp-jsptag-attribute-name">uri</span><span
 class="jsp-jsptag-whitespace">=</span><span
 class="jsp-jsptag-attribute-value">"http://java.sun.com/jstl/core"</span> <span
 class="jsp-jsptag-attribute-name">prefix</span><span
 class="jsp-jsptag-whitespace">=</span><span
 class="jsp-jsptag-attribute-value">"c"</span> <span
 class="jsp-jsptag-whitespace">%&gt;</span><br>              <span
 class="jsp-html-tag">&lt;form</span> <span class="jsp-html-argument">action=</span><span
 class="jsp-xml-value">"j_security_check"</span> <span
 class="jsp-html-argument">method=</span><span class="jsp-xml-value">"POST"</span><span
 class="jsp-html-tag">&gt;</span><br>              Username:<span
 class="jsp-html-tag">&lt;input</span> <span class="jsp-html-argument">type=</span><span
 class="jsp-xml-value">"text"</span> <span class="jsp-html-argument">name=</span><span
 class="jsp-xml-value">"j_username"</span><span class="jsp-html-tag">&gt;&lt;br&gt;</span><br>              Password:<span
 class="jsp-html-tag">&lt;input</span> <span class="jsp-html-argument">type=</span><span
 class="jsp-xml-value">"password"</span> <span class="jsp-html-argument">name=</span><span
 class="jsp-xml-value">"j_password"</span><span class="jsp-html-tag">&gt;<br>              &lt;input</span> <span
 class="jsp-html-argument">type=</span><span class="jsp-xml-value">"submit"</span> <span
 class="jsp-html-argument">value=</span><span class="jsp-xml-value">"Login"</span><span
 class="jsp-html-tag">&gt;<br>          &lt;/form&gt;</span></pre>
              </li>
              <li>Create a new <tt>html</tt> file named <tt>loginError.html</tt>
in the Web Pages folder. This is a simple error page.</li>
              <li>In the Source Editor, add the following simple error
message content to <tt>loginError.html</tt>.
                <pre class="examplecode"><span class="html-tag">	  &lt;html&gt;<br>              &lt;head&gt;<br>              	&lt;title&gt;</span>Login Test: Error logging in<span
 class="html-tag">&lt;/title&gt;<br>              &lt;/head&gt;<br>              &lt;body&gt;<br>                  &lt;h1&gt;</span>Error Logging In<span
 class="html-tag">&lt;/h1&gt;<br>                  &lt;br/&gt;<br>              &lt;/body&gt;<br>          &lt;/html&gt;</span></pre>
              </li>
            </ol>
            </div>
<!-- ======================================================================================== -->
            <h2 class="tutorial"><a name="Creating_users_roles"></a>Creating
Users and Roles on the Target Server</h2>
            <p class="tutorial">To be able to use user/password
authentication (basic login or form-based login) security in web
applications, the users and their appropriate roles have to be defined
for the target server.
To log in to a server, the user account has to exist on that server.</p>
            <p>How you define the users and roles varies according to
the target server you specified.
In this tutorial the users <tt>admin</tt> and <tt>tomcat</tt> are
used to test the security setup.
You need to confirm that these users exist on the respective servers,
and that the appropriate roles
are assigned to the users.</p>
            <div class="indent">
            <h3 class="tutorial"><a name="Tomcat"></a>Defining Roles on
Tomcat Web Server</h3>
            <p>The Tomcat server bundled with the IDE already has some
pre-defined users and roles.</p>
            <p>The basic users and roles for the Tomcat server are
defined in <tt>tomcat-users.xml</tt>.
You can find <tt>tomcat-users.xml</tt> in your <tt><i>&lt;NETBEANS_HOME&gt;</i>\enterprise3\apache-tomcat-5.5.16\conf</tt>
directory.</p>
<!--<p><b>Note:</b> The password for the user <tt>ide</tt> is generated when Tomcat is installed.
You can change the password for the user <tt>ide</tt>, or copy the password in <tt>tomcat-users.xml</tt>.</p>-->
            <pre class="examplecode"><span class="xml-tag">&lt;tomcat-users&gt;<br>    &lt;role</span> <span
 class="xml-attribute">rolename=</span><span class="xml-value">"tomcat"</span><span
 class="xml-tag">/&gt;<br>    &lt;role</span> <span
 class="xml-attribute">rolename=</span><span class="xml-value">"role1"</span><span
 class="xml-tag">/&gt;<br>    &lt;role</span> <span
 class="xml-attribute">rolename=</span><span class="xml-value">"manager"</span><span
 class="xml-tag">/&gt;<br>    &lt;role</span> <span
 class="xml-attribute">rolename=</span><span class="xml-value">"admin"</span><span
 class="xml-tag">/&gt;<br>    &lt;user</span> <span
 class="xml-attribute">username=</span><span class="xml-value">"ide"</span> <span
 class="xml-attribute">password=</span><span class="xml-value">"</span><i>(enter your password here)</i><span
 class="xml-value">"</span> <span class="xml-attribute">roles=</span><span
 class="xml-value">"manager,admin"</span><span class="xml-tag">/&gt;<br>    &lt;user</span> <span
 class="xml-attribute">username=</span><span class="xml-value">"tomcat"</span> <span
 class="xml-attribute">password=</span><span class="xml-value">"tomcat"</span> <span
 class="xml-attribute">roles=</span><span class="xml-value">"tomcat"</span><span
 class="xml-tag">/&gt;<br>    &lt;user</span> <span
 class="xml-attribute">username=</span><span class="xml-value">"role1"</span> <span
 class="xml-attribute">password=</span><span class="xml-value">"tomcat"</span> <span
 class="xml-attribute">roles=</span><span class="xml-value">"role1"</span><span
 class="xml-tag">/&gt;<br>    &lt;user</span> <span
 class="xml-attribute">username=</span><span class="xml-value">"both"</span> <span
 class="xml-attribute">password=</span><span class="xml-value">"tomcat"</span> <span
 class="xml-attribute">roles=</span><span class="xml-value">"tomcat,role1"</span><span
 class="xml-tag">/&gt;<br>&lt;/tomcat-users&gt;</span></pre>
            <h3 class="tutorial"><a name="SJSAS"></a>Defining Roles on
Sun Java System Application Server</h3>
            <p>The Sun Java System Application Server has one
pre-defined user named <tt>admin</tt>.
For this scenario you first need to use the Admin Console of the Sun
Java System Application Server to create a new user named <tt>user</tt>.
You then need to map the user to a role.</p>
            <p>Users and roles are defined in <tt>sun-web.xml</tt>
located in the WEB-INF directory of your project.</p>
            <ol>
              <li>Open the Admin Console by right-clicking the node for
the Sun Java System Application Server in the Runtime window of the
IDE. The login page for the Sun Java System Application Server opens in
your browser window. You need to log in using the admin username and
password to access the Admin Console.</li>
              <li>In the Admin Console, create a user named <tt>user</tt>
on the server.
For details on how to create a user on the Sun Java System Application
Server, see <a
 href="http://java.sun.com/javaee/5/docs/tutorial/doc/Security-Intro6.html#wp478286">Managing
Users and Groups on the Application Server</a>.</li>
              <li>In the Projects window of the IDE, double-click on <tt>sun-web.xml</tt>
located in the <tt>Web Pages/WEB-INF</tt> directory.</li>
              <li>Double-click on node Sun Web application and branches
admin and user are shown.</li>
              <li>Select admin security role mapping and add Principal
(<span style="color: rgb(204, 51, 204);">+ Group</span> ) admin</li>
              <li>Select user security role mapping and add Principal (
                <span style="color: rgb(204, 51, 204);">+ Group</span>
) user <br>
              </li>
              <br>
              <span style="font-weight: bold; color: rgb(0, 0, 0);">Note</span>:<span
 style="color: rgb(204, 51, 204);">Groups<span
 style="color: rgb(51, 0, 51);"> <span style="color: rgb(0, 0, 0);">are
needed for successful login in</span> <span
 style="color: rgb(204, 51, 204);">jdbc-realm</span></span></span>, so
if you don't plan to use jdbc-realm, you don't have to create them in <br>
              <tt>sun-web.xml</tt> , as file realm is satisfied with
"empty" group as well.<br>
            </ol>
            </div>
            <h2 class="tutorial">Configuring the Login Method</h2>
            <p>When configuring the login method for your application,
you can use the login window provided by your browser for basic login
authentication.
Alternatively, you can create a web page with a login form. Both types
of login configuration are based on user/password authentication.</p>
            <div class="indent"> <a name="Basic"></a>
            <h3 class="tutorial">Basic Login</h3>
            <p>When you use the basic login configuration, the login
window is provided by the browser.
A valid username and password is needed to access the secure content.</p>
            <p>The following steps show how to configure a basic login
for the Sun Java System Application Server.</p>
            <ol>
              <li>In the Projects window, double-click <tt>web.xml</tt>
located in the <tt>Web Pages/WEB-INF</tt> directory to open the file
in the Visual Editor.</li>
              <li>Click Security in the toolbar to open the file in
Security view and expand the Login Configuration node.</li>
              <li>Set the Login Configuration to Basic.</li>
              <li>Click Add Role and add the following Security Roles.
                <ul>
                  <li><tt>Admin</tt>, for administrators</li>
                  <li><tt>Tomcat</tt> (<span
 style="color: rgb(204, 51, 204);">User</span>), for users</li>
                </ul>
              </li>
              <li>Click Add Security Constraint, name it <tt>AdminConstraint</tt>,
and do the following:
                <ol>
                  <li>Add a Web Resource Collection, set the Resource
Name to <tt>Admin</tt> and the URL Pattern to <tt>/secureAdmin/*</tt>
and click OK.</li>
                  <li>Select Enable Authentication Constraint and click
Edit.</li>
                  <li>In the Edit Role Names dialog box, select Admin
in the left pane, click Add and then click OK.</li>
                </ol>
              </li>
              <li>Click Add Security Constraint, name it <tt>UserConstraint</tt>,
and do the following:
                <ol>
                  <li>Add a Web Resource Collection, set the Resource
Name to <tt>User</tt> and the URL Pattern to <tt>/secureUser/*</tt>
and click OK.</li>
                  <li>Select Enable Authentication Constraint and click
Edit.</li>
                  <li>In the Edit Role Names dialog box, select Admin
and Tomcat in the left pane, click Add and then click OK.</li>
<!--<li>Add Admin and Tomcat (<span style="color: rgb(204, 51, 204);">User</span>) role</li>-->
                </ol>
              </li>
            </ol>
            <a name="Form"></a>
            <h3 class="tutorial">Form Login</h3>
            <p>Using a form for login enables you to customize the
content of the login and error pages.
The steps for configuring authentication using a form are the same as
for the basic login configuration,
except that you specify the <a href="#loginform">login and error pages</a>
you created.</p>
            <p>The following steps show how to configure a login form
for the Sun Java System Application Server.</p>
            <ol>
              <li>In the Projects window, double-click <tt>web.xml</tt>
located in the <tt>Web Pages/WEB-INF</tt> directory to open the file
in the Visual Editor.</li>
              <li>Click Security in the toolbar to open the file in
Security view and expand the Login Configuration node.</li>
              <li>Set the Login Configuration to Form.</li>
              <li>Set the Form Login Page by clicking Browse and
locating <tt>login.jsp</tt>.</li>
              <li>Set the Form Error Page by clicking Browse and
locating <tt>loginError.html</tt>.</li>
              <li>Click Add Role and add the following Security Roles.
                <ul>
                  <li><tt>Admin</tt>, for administrators</li>
                  <li><tt>Tomcat</tt> (<span
 style="color: rgb(204, 51, 204);">User</span>), for users</li>
                </ul>
              </li>
              <li>Click Add Security Constraint, name it <tt>AdminConstraint</tt>,
and do the following:
                <ol>
                  <li>Add a Web Resource Collection and set the name to
                    <tt>Admin</tt> and the path to <tt>/secureAdmin/*</tt></li>
                  <li>Select Enable Authentication Constraint and click
Edit.</li>
                  <li>In the Edit Role Names dialog box, select Admin
in the left pane and click Add.</li>
                </ol>
              </li>
              <li>Click Add Security Constraint, name it <tt>UserConstraint</tt>,
and do the following:
                <ol>
                  <li>Add a Web Resource Collection and set the name to
                    <tt>User</tt> and the path to <tt>/secureUser/*</tt></li>
                  <li>Select Enable Authentication Constraint and click
Edit.</li>
                  <li>In the Edit Role Names dialog box, select Admin
and Tomcat in the left pane and click Add.</li>
<!--<li>Add Admin and Tomcat (<span style="color: rgb(204, 51, 204);">User</span>) role</li>-->
                </ol>
              </li>
            </ol>
            </div>
            <a name="jdbc"></a>
            <h2 class="tutorial">Using JDBC Authorization</h2>
            <p>If you are deploying your application to the Sun Java
System Application Server, you can also configure your application to
retrieve the authorization information from a JDBC database table.
Using this method, managing user accounts is much easier than managing
user accounts directly on the server.</p>
            <p>The JDBC authorization method is already supported in <a
 href="https://glassfish.dev.java.net/downloads/31May06.html">Glassfish
v2</a>, but if you are using Sun Java System Application Server 9.0 you
need to use a <a
 href="https://glassfish.dev.java.net/nonav/issues/showattachment.cgi/65/JDBCRealm.jar">precompiled
jar</a>.
To enable the realm <tt>jdbc-realm</tt> on the Sun Java System
Application Server you need to do the following steps.
(The steps are based on <a
 href="https://glassfish.dev.java.net/issues/show_bug.cgi?id=171">JDBCRealm
for Glassfish.</a>)</p>
            <ol>
              <li>Download <a
 href="https://glassfish.dev.java.net/nonav/issues/showattachment.cgi/65/JDBCRealm.jar">JDBCRealm.jar</a>.</li>
              <li>Copy the <tt>jar</tt> to the <tt>lib</tt> directory
located in the Sun Java System Application Server installation
directory.</li>
              <li>Add the following to the <tt>login.conf</tt> file
located in the <tt><i>&lt;APPSERVER_HOME&gt;</i>/domains/domain1/config/</tt><br>
                <pre class="examplecode">jdbcRealm {<br>net.java.glassfish.security.auth.realm.jdbc.JDBCLoginModule required;<br>};<br></pre>
              </li>
              <li>Start the server and open the Admin Console.</li>
              <li>In Configuration &gt; Security &gt; Realms, create a
new Realm named "jdbc-realm" and enter the following classname:
                <pre>net.java.glassfish.security.auth.realm.jdbc.JDBCRealm</pre>
              </li>
              <li>Add the following properties and values to the realm:
                <ul>
                  <li>jaas-context : jdbcRealm</li>
                  <li>datasource : jdbc/__default</li>
                  <li>user : APP</li>
                  <li>password : APP</li>
                  <li>find-user-query : A SQL query that return the
user's identifier when injected two parameters (username/password), like<br>
SELECT IDENTIFIER FROM PERSON WHERE USERID = ? AND PASSWORD = ? </li>
                  <li>find-groups-query : A SQL query that return group
name(s) when injected the user name, like<br>
SELECT GROUP_NAME FROM PERSON P, "GROUP" G WHERE P.GROUP_ID = G.ID AND
USERID = ?</li>
                </ul>
                <p><b>Note:</b> The user and password are for the Java
DB database server bundled with the Sun Java System Application Server.</p>
              </li>
              <li>In the Admin Console, locate Application Server/JVM
Settings/Path Settings/Classpath suffix and add the following line:
                <pre> ${com.sun.aas.installRoot}/lib/JDBCRealm.jar</pre>
              </li>
              <li>Create the appropriate tables in <tt>jdbc/__default</tt>
and add the proper data to the table,<br>
with this SQL script:<br>
                <br>
                <pre><span class="sql-keyword">create</span> <span
 class="sql-keyword">table</span> <span class="sql-identifier">"GROUP</span><span
 class="sql-identifier">"</span> (<br>    <span class="sql-identifier">ID</span>          <span
 class="sql-keyword">SMALLINT</span> <span class="sql-keyword">NOT</span> <span
 class="sql-keyword">NULL</span> <span class="sql-keyword">GENERATED</span> <span
 class="sql-identifier">ALWAYS</span> <span class="sql-keyword">AS</span> <span
 class="sql-keyword">IDENTITY</span> (<span class="sql-keyword">START</span> <span
 class="sql-keyword">WITH</span> <span class="sql-int-literal">5</span>, <span
 class="sql-identifier">INCREMENT</span> <span class="sql-keyword">BY</span> <span
 class="sql-int-literal">5</span>),<br>    <span class="sql-identifier">GROUP_NAME</span>  <span
 class="sql-keyword">VARCHAR</span>(<span class="sql-int-literal">15</span>),<br>    <span
 class="sql-keyword">CONSTRAINT</span> <span class="sql-identifier">GROUP_QU</span> <span
 class="sql-keyword">UNIQUE</span> (<span class="sql-identifier">ID</span>)<br>);<br><span
 class="sql-keyword">create</span> <span class="sql-keyword">table</span> <span
 class="sql-identifier">PERSON</span> (<br>    <span
 class="sql-identifier">IDENTIFIER</span>  <span class="sql-keyword">INT</span> <span
 class="sql-keyword">NOT</span> <span class="sql-keyword">NULL</span> <span
 class="sql-keyword">GENERATED</span> <span class="sql-identifier">ALWAYS</span> <span
 class="sql-keyword">AS</span> <span class="sql-keyword">IDENTITY</span>,<br>    <span
 class="sql-identifier">UserID</span>      <span class="sql-keyword">Varchar</span>(<span
 class="sql-int-literal">10</span>),<br>    <span class="sql-identifier">password</span>    <span
 class="sql-keyword">varchar</span>(<span class="sql-int-literal">10</span>),<br>    <span
 class="sql-identifier">GROUP_ID</span>    <span class="sql-keyword">SMALLINT</span> <span
 class="sql-keyword">NOT</span> <span class="sql-keyword">NULL</span>,<br>    <span
 class="sql-keyword">CONSTRAINT</span> <span class="sql-identifier">PERSON_PK</span> <span
 class="sql-keyword">PRIMARY</span> <span class="sql-keyword">KEY</span> (<span
 class="sql-identifier">UserID</span>),<br>    <span class="sql-keyword">CONSTRAINT</span> <span
 class="sql-identifier">PERSON_FK</span> <span class="sql-keyword">FOREIGN</span> <span
 class="sql-keyword">KEY</span> (<span class="sql-identifier">GROUP_ID</span>) <span
 class="sql-keyword">REFERENCES</span> <span class="sql-identifier">"GROUP</span><span
 class="sql-identifier">"</span> (<span class="sql-identifier">ID</span>) <span
 class="sql-keyword">ON</span> <span class="sql-keyword">DELETE</span> <span
 class="sql-keyword">RESTRICT</span><br>);<br><span class="sql-keyword">INSERT</span> <span
 class="sql-keyword">INTO</span> <span class="sql-identifier">"GROUP</span><span
 class="sql-identifier">"</span> (<span class="sql-identifier">GROUP_NAME</span>) <span
 class="sql-keyword">VALUES</span> (<span class="sql-string-literal">'user'</span>);<br><span
 class="sql-keyword">INSERT</span> <span class="sql-keyword">INTO</span> <span
 class="sql-identifier">"GROUP</span><span class="sql-identifier">"</span> (<span
 class="sql-identifier">GROUP_NAME</span>) <span class="sql-keyword">VALUES</span> (<span
 class="sql-string-literal">'admin'</span>);<br><span
 class="sql-keyword">INSERT</span> <span class="sql-keyword">INTO</span> <span
 class="sql-identifier">PERSON</span> (<span class="sql-identifier">UserID</span>,<span
 class="sql-identifier">password</span>,<span class="sql-identifier">GROUP_ID</span>) <span
 class="sql-keyword">VALUES</span> (<span class="sql-string-literal">'admin'</span>,<span
 class="sql-string-literal">'adminadmin'</span>,<span
 class="sql-int-literal">10</span>);<br><span class="sql-keyword">INSERT</span> <span
 class="sql-keyword">INTO</span> <span class="sql-identifier">PERSON</span> (<span
 class="sql-identifier">UserID</span>,<span class="sql-identifier">password</span>,<span
 class="sql-identifier">GROUP_ID</span>) <span class="sql-keyword">VALUES</span> (<span
 class="sql-string-literal">'user'</span>,<span
 class="sql-string-literal">'user'</span>,<span class="sql-int-literal">5</span>);<br><br></pre>
              </li>
            </ol>
            <p>&nbsp;</p>
            <a name="Deploy_run"></a>
            <h2 class="tutorial">Deploying and Running the Application</h2>
            <p>In the Projects window, right-click the project node and
choose Run.
After building and deploying the application to the server, the start
page opens in your web browser.
Choose the secure area which you want to access by clicking either <b>admin</b>
or <b>user</b>.</p>
            <p>After supplying the user and password, there are three
possible results: </p>
            <ul>
              <li>Password for this user is correct and user has
privileges for
secured content -&gt; secure content page is displayed</li>
              <li>Password for this user is incorrect -&gt; Error page
is displayed</li>
              <li>Password for this user is correct, but user does not
have right to access
the secured content -&gt; browser displays Error 403 Access to the
requested resource has been denied</li>
            </ul>
            <p><span style="font-weight: bold;">Note</span>: As
successful login atempt persist whole session,
you have to restart your browser to be able to login under different
user.</p>
<!-- End Content Area --> </div>
            </td>
          </tr>
        </tbody>
      </table>
      </div>
      </td>
      <td valign="top" width="196">
      <div id="contentRight">
      <div style="font-size: 11px;">&nbsp;</div>
      <div style="font-size: 11px; width: 164px; margin-right: 10px;">
      <div class="leftnavtitle"
 style="margin-bottom: 0px; border-bottom-width: medium; border-bottom-style: none;">&nbsp;</div>
      </div>
      <script
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/search00.js"
 type="text/javascript"></script>
      <script language="JavaScript" type="text/javascript">
<!--
show_search_form('Search','Go','right');
//-->
      </script>
      <noscript><span style="font-style: italic;">Search form requires
Javascript</span></noscript>
      </div>
      </td>
    </tr>
    <tr>
      <td colspan="2">
      <div id="footer">
      <div style="float: left;">MORE INFO: | <a
 href="http://www.netbeans.org/">HOME</a> | <a
 href="http://www.cafeshops.com/netbeans/">SHOP</a> | <a
 href="http://www.netbeans.org/community/issues.html">REPORT A BUG</a>
| <a href="http://www.netbeans.org/download/sitemaps/www_map.html">SITE
MAP</a> | <a href="http://www.netbeans.org/about/legal/index.html">LEGAL</a>
| <a href="http://www.netbeans.org/about/contact.html">CONTACT</a>
&nbsp;&nbsp;&nbsp; BY USE OF THIS WEBSITE, YOU AGREE TO THE <a
 href="http://www.sunsource.net/TUPPCP.html">NETBEANS POLICIES AND
TERMS OF USE</a> </div>
      </div>
      </td>
    </tr>
  </tbody>
</table>
<!-- /Servlet-Specific template --><!-- servlets and anything not on www or testwww --><!-- Begin SiteCatalyst code -->
<script language="JavaScript"
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/s_code_r.js"></script><!-- End SiteCatalyst code -->
<script
 src="Securing%20a%20Web%20Application%20in%20NetBeans%20IDE%205.5_files/urchin00.js"
 type="text/javascript"></script>
<script type="text/javascript">
_uacct = "UA-198771-2";
urchinTracker();
</script><!-- This document saved from http://www.netbeans.org/kb/articles/security-webapps.html -->
</body>
</html>