Protected WebResource access granted even though user doesn't have the required role

Apologies in advance - this must be a real newbie question, but I've read thru
alot of documentation/newsgroup info and haven't found the answer.
I'm using WL 7.0 SP1, and deploying an exploded web-app. (contents in attached
Login.zip). The web.xml defines a single protected web-resource (/yeslogin.jsp)
and a single role (PortalUser).
I've got a realm configured with all the Default* providers, and have defined
a user, a group, and the PortalUser role that hooks them together.
If I do not check the Security->Realms->myrealm->General->"Ignore security data
in deployment descriptors" checkbox, my user never seems to be associated with
the role I've defined. (I can see this from the output of the DefaultAuditor set
to INFORMATION severity) when access control checks are done - so I always get
a 403 (Access denied).
If I do check the "Ignore security data in deployment descriptors" box, reboot
WL and re-deploy my web-application then the audit trail does show that my user
is associated with my role, and I am able to run the application.
The problem is, when configured this way if I have another user who does not have
that role, they are also able to use the application. The DefaultAuditRecorder.log
file show that the "Role Manager Audit Event" for checking access to the protected
resource has been invoked, but then the status is SUCCEED!?!?!
Any pointer to what I've done wrong, or the docs that tell me how to do this right
would be WAY appreciated.
This same web-application works across a range of various J2EE 1.3 compliant web-containers,
but I have not figured out how to configure WL 7.0 to let it work.
[Login.zip]

I tried your web app and it worked for me. I hit the URL that you protected:
http://localhost:7001/login/login_page.jsp
Logging in as a bad users popped up your error page.
Logging in as a users in the PortalUser role ( I changed that to a role I
already had) let me hit the
your login page.
One thing. Usually, you let the users hit your protected page and you let
the web container do the work and pop
up your login form instead of you programmatically sending them to the login
page. If you change web.xml to:
<login-config>
<auth-method>BASIC</auth-method>
<realm-name>myrealm</realm-name>
</login-config>
It will just pop up the browsers dialog.
Also, don't check the "ignore security data in deployment descriptors". In
your case you ARE using the deployment
descriptor.
BTW. I can ONLY get web app deployment descriptor security to work in WLS
7.0 sp1 and CAN NOT get the
console web app security policy to work! I have an unanswered post on this.
See the post:
Console based web app security
"Dave Clegg" <[email protected]> wrote in message
news:[email protected]...
>
Apologies in advance - this must be a real newbie question, but I've readthru
alot of documentation/newsgroup info and haven't found the answer.
I'm using WL 7.0 SP1, and deploying an exploded web-app. (contents inattached
Login.zip). The web.xml defines a single protected web-resource(/yeslogin.jsp)
and a single role (PortalUser).
I've got a realm configured with all the Default* providers, and havedefined
a user, a group, and the PortalUser role that hooks them together.
If I do not check the Security->Realms->myrealm->General->"Ignore securitydata
in deployment descriptors" checkbox, my user never seems to be associatedwith
the role I've defined. (I can see this from the output of theDefaultAuditor set
to INFORMATION severity) when access control checks are done - so I alwaysget
a 403 (Access denied).
If I do check the "Ignore security data in deployment descriptors" box,reboot
WL and re-deploy my web-application then the audit trail does show that myuser
is associated with my role, and I am able to run the application.
The problem is, when configured this way if I have another user who doesnot have
that role, they are also able to use the application. TheDefaultAuditRecorder.log
file show that the "Role Manager Audit Event" for checking access to theprotected
resource has been invoked, but then the status is SUCCEED!?!?!
Any pointer to what I've done wrong, or the docs that tell me how to dothis right
would be WAY appreciated.
This same web-application works across a range of various J2EE 1.3compliant web-containers,
but I have not figured out how to configure WL 7.0 to let it work.

Similar Messages

  • I own CS5 on my work laptop which was just stolen. Do I need to buy CS from scratch or can I transfer CS5 to a new computer even though I don't have the one that CS5 is on?

    I own CS5 on my work laptop which was just stolen. Do I need to buy a new CS from scratch or can I transfer CS5 to a new computer even though I don't have the computer that CS5 is on? Company purchased CS5 before the whole creative cloud leasing thing started, but after discs.

    You can use web chat to remove authorization from the computer that was stolen:
    Serial number and activation support
    You can download the software again here:
    Other downloads

  • Export failing with "The user does not have the required rights to perfrom

    We are testing an upgrade to BOXI 3.1.  We use the CrystalReportViewer .net web control to view the report.  When the export button is clicked and the Crystal Reports file format is selected, the following error message is displayed:
    "The user does not have the required rights to perfrom this operation. Please contact your administrator. "
    Notice that perfrom is not spelled correctly.  This is what actually gets displayed.
    I'm not too concerned about the spelling, but I do want to fix the error.  So I checked the security on the folder and the user does have full control.  Both advanced security options are selected:
    -View document instances that the user owns
    -Export the report's data
    So what else could be causing this?

    I had applied the full control access to the wrong group.  Once I applied that access to the user that actually generates the report, it worked.

  • How do I automatically sync outlook contacts to iphone contacts? My email and calendar does this but even though in settings I have the contacts ON it does not.

    How do I get my outlook contacts to automatically sync to my iphone 5? In settings I have it set up to do so BUT it does not. My email and calendar updates every 1/2 hour but I can't get my contacts to auto update. Please advise.

    Start with your finger at the bottom of the screen (about even with the home button) and swipe in an upward motion.  There should be a row of icons at the top of a grey field.  if the quarter-moon icon is bright white, tap it.  If it was (and still is) dark, take the iPhone in to be evaluated by a qualified technician.

  • Itunes is charging me for something my brother tried to buy, even though I didn't have the money on my account. I can't download free apps or anything cause they say I owe them 36 dollars for something I couldn't even afford.

    I was trying to download free apps, and found out Itunes wants to charge me 36 dollars for something my brother was trying to download for his Cartoon Wars game on his ipod. They charged me the money and now I can't do anything because they want the 36 dollars. Need to get these charges taken off so I can use the card again.

    Just need to find a way to get a hold of someone who can fix this.

  • I have an older version of Firefox (3.5), can I still get support via chat even though I don't have the newest version?

    This is more of a policy question than a technical one -- just wandering if Mozilla puts a limit on who is eligible for support based on software version or anything else? Thanks.

    Currently we are support Firefox 3.6.24 and 8, and not only support, you are using an outdated version where no security patch, vulenerability updated and many more, in pc not only antivirus, you should keep always browser, browser plugin, java, reader up to date
    you can get latest version of Firefox from here
    * getfirefox.com

  • My iphone 5 is showing my imessage to someone has been delievered but isnt stating that it has be read, even though those i text have the setting on. It worked just after new year but somehow doesnt seem to work not sure how to fix it :( help anyone

    please help im not sure how to fix this problem. It should work but has stopped working for some reason.

    its already sorted my friend who has it already swwitched on turned it off and switched it back on again and its working on my phone okay now just need to check with other contacts if they have it on or not but thanks

  • I have an iMacG5 that I have always had hardwired for internet now want to go wireless.  Apple store tells me not possible even though user's guide intsructs how to. Need airport card, base etc.

    Need to go wireless with iMacgG5.  No airport card installed.  Apple employee tells me not possible to go wireless with this machine even though user's guide instructs how to.  ?????

    The early iMac G5s had optional wireless via an Airport Extreme card. Later ones came with it preinstalled. If System Profiler (in Applications > Utilities) shows your Machine ID as "PowerMac8,1" it would have been optional, any number 8,2 and up means you should have built in wireless.
    The simplest wasy to access wireless today is via a wireless USB adapter. However, you can't simply run to the store and buy any old gadget. Most on store shelves lack the required Mac OX software support files. This one:
    Newer Technology MAXPower 802.11n/g/b USB Adapter + Plug and play direct or with extension cradle
    plugs into a USB port and comes with the proper Mac drivers. It's also faster than the Airport Extreme, which is limited to "g" speeds. It's also much cheaper that original Apple cards, which are getting harder to find. I like the cradle that allows placing the device for best reception.

  • ITunes music files cannot be edited, and new music files imported.  The messages says I do not have enough access privileges even though I am the administrator of the system.

    Since installing the latest version of iTunes all my music files cannot be edited, and I cannot import new music files into iTunes.  The messages says I do not have enough access privileges even though I am the administrator of the system.  If anyone can help me sort this out I would be really grateful.  I have checked the read and write privileges for all the iTunes folders and it all seems in order so I can't understand it.
    In general, I am getting really frustrated with Apple.  They seem to be getting ever more controlling in their approach to their consumers.  I need to edit music file information as I am a dj.  And why can't I import music, unless I buy it from iTunes?  Most of all, why can't I use the devices I paid a lot of money for in the way I want to use them, and not be forced to coerced to use apple's fee paying services (iCloud, iTunes).
    I have used apple computers since the early 1990's, but in the last year I have gotten rid of my iPhone and my iPad and replaced them with Android devices.  Much better and much less control.  Perhaps it is time to switch from Apple altogether.

    Hi
    Read this About Disk Utility's Repair Disk Permissions feature
    and OS X Mavericks: If you don’t have the correct permissions to open a file or folder
    Does this help?
    Jim

  • Why does Apple not give a list of error messages and possible solutions? I have the (-54) error continually that has suddenly appeared and cannot find a solution, even though other users seem to have the same problem.

    Why does Apple not give a list of error messages and possible solutions? I have the (-54) error continually that has suddenly appeared and cannot find a solution, even though other users seem to have the same problem.

    This is a user to user forum.  Apple isn't here and won't answer you.  You need to contact Apple directly.  You can use the Contact button at the bottom of the screen.

  • Hi, I can't access my iTunes store even though I had updated to the latest version of the iOS. It always shows "the request could not be processed" when I tried to access the iTunes store. Pls help..

    Hi, I can't access my iTunes store even though I had updated to the latest version of the iOS. It always shows "the request could not be processed" when I tried to access the iTunes store. This has been going on for the past 3 days already. Pls help..

    Many thanks b Noir
    This is a copy of ONEof the keys  in the registry I changed  as told by Apple support today. I also have changed others as instructed by GEAR  software support to manually delete GEAR drivers (that I had installed but couldn't delete some of the others  they mentioned from Windows system 32. Then some bright spark at work told me I need the Gear drivers so  I downloaded the software and installed again.
    Sorry, just this minute went to insert image  and it is giving me a message saying this sort of content  is not allowed?.
    The most recent key I altered is in: HKey _local _machine. System\class - 4D36E965-E325-11CEBFC1-08002BE10318. Upper Filter data: Upper filter NTIDrvr  SiRem GEARAspiWDN.
    The GEARsoftware info about manually deleting  GEAR drive is from:
    http://www.gearsoftware.com/wiki/index.php?title=DRIVERS:_Windows_-_Updating%2C_ removing%2C_64_bit_versions%2C_etc
    I hope you can help

  • My dock disappears even though I don't have hiding mode?

    Recently my dock has been acting really strange. Even though I don't have "hiding-mode" on in the System Preferences, it keeps disapearing from the screen! I have tried to turn the computer off, I have also tried turning on and off the hiding-mode (as well as all the other "modes" in the Dock-section) but it doesn't help. This is really annoying me as I hate when I can't see my dock... I have no idea why this happened. I hadn't touched anything in the System Preferences but suddenly one day this just stared to happen. Does anyone know what I should do?
    The top bar (I don't know its name...) where the wifi-connection, the battery percent, time and where the apple-symbol is (that gives you the opportunity to log out/turn off etc.) also "gone"!! It comes back when I move my mouse cursor over it, just like the dock, but I have no idea how to turn the hiding mode off.
    They both stared disapeareing at the same time.
    Has this happened to anyone else, and what am I supposed to do?

    Please read this whole message before doing anything.
    This procedure is a test, not a solution. Don’t be disappointed when you find that nothing has changed after you complete it.
    Step 1
    The purpose of this step is to determine whether the problem is localized to your user account.
    Enable guest logins* and log in as Guest. Don't use the Safari-only “Guest User” login created by “Find My Mac.”
    While logged in as Guest, you won’t have access to any of your personal files or settings. Applications will behave as if you were running them for the first time. Don’t be alarmed by this; it’s normal. If you need any passwords or other personal data in order to complete the test, memorize, print, or write them down before you begin.
    Test while logged in as Guest. Same problem?
    After testing, log out of the guest account and, in your own account, disable it if you wish. Any files you created in the guest account will be deleted automatically when you log out of it.
    *Note: If you’ve activated “Find My Mac” or FileVault, then you can’t enable the Guest account. The “Guest User” login created by “Find My Mac” is not the same. Create a new account in which to test, and delete it, including its home folder, after testing.
    Step 2
    The purpose of this step is to determine whether the problem is caused by third-party system modifications that load automatically at startup or login, or by a peripheral device.
    Disconnect all wired peripherals except those needed for the test, and remove all aftermarket expansion cards. Boot in safe mode and log in to the account with the problem. Note: If FileVault is enabled, or if a firmware password is set, or if the boot volume is a software RAID, you can’t do this. Ask for further instructions.
    Safe mode is much slower to boot and run than normal, and some things won’t work at all, including Wi-Fi on certain iMacs.  The next normal boot may also be somewhat slow.
    The login screen appears even if you usually log in automatically. You must know your login password in order to log in. If you’ve forgotten the password, you will need to reset it before you begin.
    Test while in safe mode. Same problem?
    After testing, reboot as usual (i.e., not in safe mode) and verify that you still have the problem. Post the results of steps 1 and 2.

  • My MacBook Pro will not open any application or program that requires internet, even though I am connected to the web.

    My MacBook Pro will not open any app or program that requires Internet, even though I am connected to the web. I recently installed Norton AntiVirus and think it may have changed a setting that I couldn't find. I uninstalled Norton and it didn't help. Every time I open Safari, iTunes or any other program that tries to connect to the Internet, it crashes. Strangely enough, Skype still works, but nothing else.
    I have OSx 10.6.8.
    I have tried erasing plists, and all the standard troubleshooting, ie resetting modem, restarting computer, reloading Safari from disk.
    Any help would be greatly appreciated. Thank you in advance.

    Change your router channel.  Sometimes this is all you will have to do.
    Power cycling the router.  Read the router's user manual or contact their tech support for instructions.
    System Preferences/Internet & Network/Network
    Unlock the padlock
    Locations:  Automatic
    Highlight Airport
    Click the Assist Me button
    In the popup window click the Diagnostic button.
    System Preferences/Network- Unlock padlock.  Highlight Airport.  Network Name-select your name.  Click on the Advanced button.  Airport/Preferred Networks-delete all that is not your network.
    Place a check mark next to "Remember networks this computer has joined."  Click the OK button and lock the padlock.  Restart your computer.
    http://support.apple.com/kb/TS1920 Mac OS: How to release and renew a DHCP lease
    No internet connection (wireless)
    Check to see if an extra entry is present in the DNS Tab for your wireless connection (System Preferences/Network/Airport/Advanced/DNS).
    Delete all extra entries that you find.
    Place a check mark next to "Remember networks this computer has joined."
    Other resources to check into:
    Troubleshooting Wi-Fi issues in OS X Lion and Mac OS X v10.6
    Netspot
    How to diagnose and resolve Wi-Fi slow-downs
    Pv6 troubleshooting
    Mac OS X 10.6 Help:  Solving problems with connecting to the Internet
    What Affects Wireless Internet?
    Solutions for connecting to the Internet, setting up a small network, and troubleshooting
    I uninstalled Norton and it didn't help.
    To properly uninstall Norton software follow these instructions - Locate Symantic Solutions folder inside the Applications folder at the root level of your HD, launch the Symantec Uninstaller application, select the Symantec AntiVirus Corporate, Norton AntiVirus & Norton AntiVirus Auto-Protect entries and click the Uninstall button. 
    Confirm your decision when prompted and then enter your administrator password in the space provided.
    Retart your computer & Norton should be gone for good.
    If the above does not work, download a copy of Symantec’s RemoveSymantecMacFiles removal utility.  This utility will launch Terminal & remove the Norton components.

  • The lens correction option in Lightroom 5 is for the Tamron 28-75mm lens, rather than the correct Tamron 18-270mm, even though it's correct in the Library metadata. How can I fix this?

    The lens correction option in Lightroom 5 is for the Tamron 28-75mm lens, rather than the correct Tamron 18-270mm, even though it's correct in the Library metadata. How can I fix this?

    Are you shooting RAW or JPG or some of both?
    When you say it won't let you change it, does that mean there are no lens profiles at all, or no lens profiles that match your lens? If you set Auto or Default you can select any lens you want from the list of manufacturers and profiles and then the Setup says Custom.  Of course this lens may not be the correct lens, but saying you cannot change it suggests there are no manufacturers or lenses listed on the dropdowns.
    Most lens profiles are for RAW only, so if you shoot a mixture of RAW and JPG then for the JPGs the lens profile may not exist.  If you are enabling Lens Profiles and have Auto or Default set and it chooses the wrong one then it may just be choosing the top one in the list for Canon if the specific profile doesn't exist for JPGs.
    If you are shooting raw and the profile does exist then you should be able to correct the situation:  In the list select the correct profile, then choose Setup:  Save New Lens Profile Defaults, and select Default from the Setup instead of Auto and it should pick the correct lens every time.  Assuming it does do that, then you can set Enable Lens Profiles = checked and Setup: Default and set those as your new Lightroom Defaults and it should pick the right lens.
    If you are shooting JPG then the lens profile may well not exist and there's nothing you can do about that except not shoot JPG.  If you feel like it you can hack a raw profile to be a jpg profile and put that hacked copy in the user-lens-profile area and LR will see it.

  • HT1386 Why is it that even though I've deleted all the songs on my ipod, the songs still show up in gray letters in spite on not being able to hear them..

    Why is it that even though I've deleted all the songs on my ipod, the songs still show up in gray letters in spite on not being able to hear them.

    First of all, try another port on your computer. Some ports are not connected direct to the motherboard and do not recognize the iPod as well as those that are. Reset the iPod each time you connect it to another port.
    Still no joy, see these.
    Your Windows PC doesn't recognize iPod.
    iPod appears in Windows Explorer but does not appear in iTunes.
    iPod does not appear in iTunes.
    Fast user switching in Windows XP is not supported.
    Strange iPod behavior.
    When restoring the iPod, put it into disk mode first.
    Putting iPod into disk mode.

Maybe you are looking for

  • Any tips on managing reminders = tasks in ical?

    I have Palm on my Dell. I'm moving to MacbookPro. I got my contacts to Address Book using Vcard. I don't have tons of calendar entries so used the Vcal option to move them one at a time to iCal. Now I'm down to moving Palm tasks to my Mac. In terms o

  • CS2 - Where is the Gradient?

    I was emailed this pdf logo by a client. I placed it into CS2 and flattened transparency. In the logo, there is a white circular gradient that is visible; yet it doesnt show up on any of the layers and cannot be selected. When I copy and paste the lo

  • User terms for Adobe Reader

    I downloaded Adobe Reader on a new computer and everything was working fine. I went to use it today and I get a pop up that says I must agree to the user terms before I can continue. How can I do that?

  • I upgraded to mountain lion and now all of my notes in Mail are gone!

    I have notes turned on in i CLoud system preferences but after the update of the database when I started Mail for the first time, all of my notes in Mail were gone!  Also, all of my folders/mailboxes are gone too.  Can I get them back?

  • How to write hierarichal query when a child has multuple parent

    Following sql is not able to provide the results where ever child has more then one parent, can somebody help me write the query to deal with this scenario select w.s2_child_contract_id, w.s2_parent_contract_id, w.s2_modifier_type_nm, LEVEL, connect_