keeps redirecting to logon page....

Rubens Carlos de Souza Gomes <rgomes-VLOl4Yabd7I4j/[email protected]> Thu, 7 Aug 2003 16:31:28 -0300
Newsgroups gmane.comp.java.securityfilter.user
Message-ID <C7A1A91FB3DCD311B1BD00508B62B75104FBDDD2@DIGINET_SP>
I am using JDBCRealm on Tomcat 4 along with Struts and security filter.
When after passing thru the logon page, I try to access a link in the
/secure area the server redirects to the logon page.  I had this problem
when using container management security, and then I switched to using the
security filter.  But the same problem remains.  Can someone check my
configurations below for any potential problems?  Do I need to implement any
code to make security management to work?

<?xml version="1.0" encoding="ISO-8859-1"?>
<!--
  Author     : Rubens S. Gomes 
  Date       : $Date: 2003/08/07 16:30:57 $ (UTC - Greenwich Mean Time)
  File       : web.xml
  Revision   : $Revision: 1.13 $

  Purpose    :  
    Web NMS Application deployment descriptor.
    original path: <container>/webapps/webnms/WEB-INF/web.xml
 
  Limitations:
    Written and tested on Tomcat running on Sun UNIX Solaris
  
 ident "@(#)$Id: web.xml,v 1.13 2003/08/07 16:30:57 rgomes Exp $"
-->

<!DOCTYPE web-app PUBLIC "-//Sun Microsystems, Inc.//DTD Web Application
2.3//EN" 
   "http://java.sun.com/dtd/web-app_2_3.dtd">

<web-app>

  <display-name>Web NMS Application Portal</display-name>
  <description>
    Web based NMS Application Portal to run several internal applications.
  </description>

  <!-- Parameters for the application -->
  <context-param>
    <param-name>timezone</param-name>
    <param-value>America/Sao_Paulo</param-value>
  </context-param>

  <!-- Filtering -->
   <filter>
      <filter-name>Security Filter</filter-name>
      <filter-class>org.securityfilter.filter.SecurityFilter</filter-class>
      <init-param>
         <param-name>security-config</param-name>
         <param-value>/WEB-INF/securityfilter-config.xml</param-value>
         <description>Security Configuration File</description>
      </init-param>
      <init-param>
         <param-name>validate</param-name>
         <param-value>true</param-value>
         <description>Validate config file if set to true</description>
      </init-param>
   </filter>

   <!-- map all requests to the SecurityFilter, control what it does with
configuration settings -->
   <filter-mapping>
      <filter-name>Security Filter</filter-name>
      <url-pattern>/*</url-pattern>
   </filter-mapping>

  <!--  Struts Servlet Configuration -->
  <servlet>
    <servlet-name>action</servlet-name>
    <display-name>action</display-name>
    <description>Struts Action Servlet</description>
    <servlet-class>org.apache.struts.action.ActionServlet</servlet-class>
    <init-param>
      <param-name>application</param-name>
 
<param-value>diveo.nms.webclient.locale.ApplicationResources</param-value>
    </init-param>
    <init-param>
      <param-name>config</param-name>
      <param-value>/WEB-INF/struts-config.xml</param-value>
    </init-param>
    <init-param>
      <param-name>debug</param-name>
      <param-value>1</param-value>
    </init-param>
    <init-param>
      <param-name>detail</param-name>
      <param-value>1</param-value>
    </init-param>
    <load-on-startup>2</load-on-startup>
  </servlet>

  <!-- Action Servlet Mapping -->
  <servlet-mapping>
    <servlet-name>action</servlet-name>
    <url-pattern>*.do</url-pattern>
  </servlet-mapping>

  <!-- Session Timeout -->
  <session-config>
    <session-timeout>15</session-timeout> <!-- 15 minutes -->
  </session-config>

  <!--  Welcome file list -->
  <welcome-file-list>
    <welcome-file>logon.jsp</welcome-file>
  </welcome-file-list>

  <!-- Error Pages -->
  <error-page>
    <error-code>400</error-code>
    <location>/400.jsp</location>
  </error-page>
  <error-page>
    <error-code>403</error-code>
    <location>/403.jsp</location>
  </error-page>
  <error-page>
    <error-code>404</error-code>
    <location>/404.jsp</location>
  </error-page>
  <error-page>
    <error-code>500</error-code>
    <location>/500.jsp</location>
  </error-page>
  <error-page>
    <error-code>503</error-code>
    <location>/503.jsp</location>
  </error-page>

  <!-- Tag Library -->
  <taglib>
    <taglib-uri>/WEB-INF/struts-bean.tld</taglib-uri>
    <taglib-location>/WEB-INF/struts-bean.tld</taglib-location>
  </taglib>
  <taglib>
    <taglib-uri>/WEB-INF/struts-tiles.tld</taglib-uri>
    <taglib-location>/WEB-INF/struts-tiles.tld</taglib-location>
  </taglib>
  <taglib>
    <taglib-uri>/WEB-INF/struts-html.tld</taglib-uri>
    <taglib-location>/WEB-INF/struts-html.tld</taglib-location>
  </taglib>
  <taglib>
    <taglib-uri>/WEB-INF/struts-logic.tld</taglib-uri>
    <taglib-location>/WEB-INF/struts-logic.tld</taglib-location>
  </taglib>
  <taglib>
    <taglib-uri>/WEB-INF/struts-nested.tld</taglib-uri>
    <taglib-location>/WEB-INF/struts-nested.tld</taglib-location>
  </taglib>
  <taglib>
    <taglib-uri>/WEB-INF/taglibs-datetime.tld</taglib-uri>
    <taglib-location>/WEB-INF/taglibs-datetime.tld</taglib-location>
  </taglib>
  <taglib>
    <taglib-uri>/WEB-INF/taglibs-session.tld</taglib-uri>
    <taglib-location>/WEB-INF/taglibs-session.tld</taglib-location>
  </taglib>
  <taglib>
    <taglib-uri>/WEB-INF/c.tld</taglib-uri>
    <taglib-location>/WEB-INF/c.tld</taglib-location>
  </taglib>
  <taglib>
    <taglib-uri>/WEB-INF/fmt.tld</taglib-uri>
    <taglib-location>/WEB-INF/fmt.tld</taglib-location>
  </taglib>
  <taglib>
    <taglib-uri>/WEB-INF/taglibs-log.tld</taglib-uri>
    <taglib-location>/WEB-INF/taglibs-log.tld</taglib-location>
  </taglib>
  <taglib>
    <taglib-uri>/WEB-INF/webnms.tld</taglib-uri>
    <taglib-location>/WEB-INF/webnms.tld</taglib-location>
  </taglib>
 
  <!-- JNDI name reference for the UserDAO Object Factory   -->
  <resource-env-ref>
    <description>Object Factory for User DAO Instance</description>
    <resource-env-ref-name>dao/UserDAOFactory</resource-env-ref-name>
 
<resource-env-ref-type>diveo.nms.client.dao.user.UserDAO</resource-env-ref-t
ype>
  </resource-env-ref>

 <!-- JNDI name reference for Oracle DB connection pool -->
  <resource-ref>
    <description>DB Connection</description>
    <res-ref-name>jdbc/oracle</res-ref-name>
    <res-type>javax.sql.DataSource</res-type>
    <res-auth>Container</res-auth>
  </resource-ref>

</web-app>



<?xml version="1.0" encoding="ISO-8859-1"?>
<!--
  Author     : Rubens S. Gomes 
  Date       : $Date: 2003/08/07 16:30:56 $ (UTC - Greenwich Mean Time)
  File       : securityfilter-config.xml
  Revision   : $Revision: 1.1 $

  Purpose    :  
    Security Filter configuration.
 
  Limitations:
    Written and tested on Tomcat running on Sun UNIX Solaris
  
 ident "@(#)$Id: securityfilter-config.xml,v 1.1 2003/08/07 16:30:56 rgomes
Exp $"
-->
<!DOCTYPE securityfilter-config PUBLIC
    "-//SecurityFilter.org//DTD Security Filter Configuration 1.0//EN"
    "http://www.securityfilter.org/dtd/securityfilter-config_1_0.dtd">

<securityfilter-config>

  <security-constraint>
    <display-name>Security 1</display-name>
    <web-resource-collection>
      <web-resource-name>encripted_area</web-resource-name>
      <url-pattern>/logon.jsp</url-pattern>
      <http-method>DELETE</http-method>
      <http-method>GET</http-method>
      <http-method>POST</http-method>
      <http-method>PUT</http-method>
    </web-resource-collection>
    <auth-constraint>
      <role-name>*</role-name>
    </auth-constraint>
    <user-data-constraint>
      <transport-guarantee>CONFIDENTIAL</transport-guarantee>
    </user-data-constraint>
  </security-constraint>

  <security-constraint>
    <display-name>Security 2</display-name>
    <web-resource-collection>
      <web-resource-name>secure_area</web-resource-name>
      <url-pattern>/secure/*</url-pattern>
      <http-method>DELETE</http-method>
      <http-method>GET</http-method>
      <http-method>POST</http-method>
      <http-method>PUT</http-method>
    </web-resource-collection>
    <auth-constraint>
      <role-name>ADMINISTRATOR</role-name>
      <role-name>OPERATOR</role-name>
    </auth-constraint>
    <user-data-constraint>
      <transport-guarantee>NONE</transport-guarantee>
    </user-data-constraint>
  </security-constraint>

  <login-config>
    <auth-method>FORM</auth-method>
    <form-login-config>
      <form-login-page>/logon.jsp</form-login-page>
      <form-error-page>/logon_error.jsp</form-error-page>
      <form-default-page>/secure/index.jsp</form-default-page>
    </form-login-config>
  </login-config>

  <security-role>
    <description>Administrator of the system</description>
    <role-name>ADMINISTRATOR</role-name>
  </security-role>
  <security-role>
    <description>All the operators</description>
    <role-name>OPERATOR</role-name>
  </security-role>

  <realm className="org.securityfilter.realm.catalina.CatalinaRealmAdapter"
/>
  <realm className="org.apache.catalina.realm.JDBCRealm">
    <realm-param name="driverName" value="oracle.jdbc.driver.OracleDrive"/>
    <realm-param name="debug" value="99"/>
    <realm-param name="connectionURL"
value="jdbc:oracle:thin:@oracle.noc.spo.dcn:1521:NMSTEST"/>
    <realm-param name="connectionName" value="nms"/>
    <realm-param name="connectionPassword" value="nms"/>
    <realm-param name="userTable" value="APPLICATION_USER"/>
    <realm-param name="userNameCol" value="USER_ID"/>
    <realm-param name="userCredCol" value="PASSWORD"/>
    <realm-param name="userRoleTable" value="APPLICATION_USER_ROLE"/>
    <realm-param name="roleNameCol" value="ID"/>
  </realm>

</securityfilter-config>

<!-- 

  Author     : Rubens S. Gomes 
  Date       : $Date: 2003/08/07 16:30:56 $ (UTC - Greenwich Mean Time)
  File       : webnms.xml
  Revision   : $Revision: 1.6 $
  Purpose    :  
    Context configuration for the WebNMS front end system.
    original path: <container>/webapps/webnms.xml
 
  Limitations:
    Written and tested on Tomcat running on Sun UNIX Solaris
  
 ident "@(#)$Id: webnms.xml,v 1.6 2003/08/07 16:30:56 rgomes Exp $"

 -->

<!--    **************************    -->
<!--    WebNMS Application Context    -->
<!--    **************************    -->

<Context path="/webnms"
         docBase="webnms.war"
         reloadable="true"
         cookies="true"
         debug="99"
         useNaming="true"
         workDir="/var/opt/webnms/work">

  <Logger className="org.apache.catalina.logger.FileLogger"
          verbosity="1"
          directory="/var/opt/webnms/logs"  
          prefix="tomcat_webnms." suffix=".log"
          timestamp="true"/>

  <!--   Database Realm    -->

  <Realm className="org.apache.catalina.realm.JDBCRealm" 
         debug="99"
         driverName="oracle.jdbc.driver.OracleDriver"
         connectionURL="jdbc:oracle:thin:@oracle.noc.spo.dcn:1521:NMSTEST"
         connectionName="nms" 
         connectionPassword="nms"
         userTable="APPLICATION_USER" 
         userNameCol="USER_ID" 
         userCredCol="PASSWORD"
         userRoleTable="APPLICATION_USER_ROLE" 
         roleNameCol="ID"/>

  <!-- JNDI User DAO Factory Resource -->

  <Resource name="dao/UserDAOFactory"
            auth="Container"
            type="diveo.nms.client.dao.user.UserDAO"
            scope="shareable"
            description="UserDAO Factory"/>

  <ResourceParams name="dao/UserDAOFactory">
    <parameter>
      <name>factory</name>
      <value>diveo.nms.client.dao.user.UserDAOFactory</value>
    </parameter>
  </ResourceParams>

  <!--  JNDI Oracle Database Resource -->

  <Resource name="jdbc/oracle" 
            auth="Container" 
            type="javax.sql.DataSource"
            scope="shareable"
            description="Database for WebNMS Application"/>

  <ResourceParams name="jdbc/oracle">
    <parameter>
      <name>factory</name>
      <value>org.apache.commons.dbcp.BasicDataSourceFactory</value>
    </parameter>
    <parameter>
      <name>driverClassName</name>
      <value>oracle.jdbc.driver.OracleDriver</value>
    </parameter>
    <parameter>
      <name>url</name>
      <value>jdbc:oracle:thin:@oracle.noc.spo.dcn:1521:NMSTEST</value>
    </parameter>
    <parameter>
      <name>username</name>
      <value>nms</value>
    </parameter>
    <parameter>
      <name>password</name>
      <value>nms</value>
    </parameter>
    <parameter>
      <name>maxActive</name>
      <value>50</value>
    </parameter>
    <parameter>
      <name>maxIdle</name>
      <value>10</value>
    </parameter>
    <parameter>
      <name>maxWait</name>
      <value>5</value>
    </parameter>
    <parameter>
      <name>validationQuery</name>
      <value>select sysdate from dual</value>
    </parameter>
    <parameter>
      <name>defaultAutoCommit</name>
      <value>true</value>
    </parameter>
    <parameter>
      <name>removeAbandoned</name>
      <value>true</value>
    </parameter>
    <parameter>
      <name>removeAbandonedTimeout</name>
      <value>60</value>
    </parameter>
  </ResourceParams> 

</Context>