user-data-constraint, role-specific home pages

[email protected] (Steven J. Owens) Mon, 30 Aug 2004 15:40:28 -0400
Newsgroups gmane.comp.java.securityfilter.user
Message-ID <20040830194028.GC7724@localhost>
Hi guys,

     We've just started using securityfilter for our tomcat-based
webapp.  So far so good.  I haven't looked at the source yet, but
I have a couple of questions:

1) I was about to write a simple servlet filter to redirect non-SSL
requests over to the same URL, but with an https:// prefix.  However,
the securityfilter homepage mentions support for user-data-constraint
(requiring the user to access the site via SSL) coming sometime
RealSoonNow.  

     Any idea if that's there yet, or if not, when it will be?  

     Would user-data-constraint support this sort of URL rewriting, or
does it just take the user to an error page?

2) We have a couple of different roles for our users.  I'd like to set
it up so different roles go to different home pages in the app.  

I could kludge this easily enough by having the default home page look
at the user's role and redirect them to the appropriate page, but I'd
rather have it explicitly defined in the XML config file.  Does this
sound sane and/or doable?

-- 
Steven J. Owens
[email protected] / (412) 401-8060 cell / (412) 578-9817 house
| "I'm going to make broad, sweeping generalizations and strong,
|  declarative statements, because otherwise I'll be here all night and
|  this document will be four times longer and much less fun to read.
|  Take it all with a grain of salt." 
|  - http://darksleep.com/notablog


-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click