resin 访问权限控制

1. IP

  web.xml下加入

    <security-constraint>
      <web-resource-collection>
        <url-pattern>/*</url-pattern>
      </web-resource-collection>
      <ip-constraint>
        <allow>ip</allow>
      </ip-constraint>
    </security-constraint>

2. user

      <authenticator type="com.caucho.server.security.XmlAuthenticator">
        <init>
          <user>Harry Potter:quidditch:user</user>
          <password-digest>none</password-digest>
        </init>
      </authenticator>
      <login-config auth-method='basic'/>
      <security-constraint url-pattern='*' role-name='user'/>

3. IP + user

    <security-constraint>
   <web-resource-collection>
    <web-resource-name>Protected Context</web-resource-name>
    <url-pattern>/*</url-pattern>
   </web-resource-collection>
         <ip-constraint>
        <allow>ip</allow>
      </ip-constraint>
   <auth-constraint role-name='admin' />
</security-constraint>

<authenticator type="com.caucho.server.security.XmlAuthenticator">
   <init>
    <user name='admin' password='admin' roles='admin' />
    <password-digest>none</password-digest>
   </init>
</authenticator>


<login-config>
   <auth-method>BASIC</auth-method>
    <form-login-config> <form-login-page>/login.jsp</form-login-page>
    <form-error-page>/error.jsp</form-error-page> </form-login-config>
</login-config>
posted @ 2012-09-14 14:11  haohao_jk  阅读(452)  评论(0)    收藏  举报