resin 访问权限控制
1. IP
web.xml下加入
<security-constraint>
<web-resource-collection>
<url-pattern>/*</url-pattern>
</web-resource-collection>
<ip-constraint>
<allow>ip</allow>
</ip-constraint>
</security-constraint>
2. user
<authenticator type="com.caucho.server.security.XmlAuthenticator">
<init>
<user>Harry Potter:quidditch:user</user>
<password-digest>none</password-digest>
</init>
</authenticator>
<login-config auth-method='basic'/>
<security-constraint url-pattern='*' role-name='user'/>
3. IP + user
<security-constraint>
<web-resource-collection>
<web-resource-name>Protected Context</web-resource-name>
<url-pattern>/*</url-pattern>
</web-resource-collection>
<ip-constraint>
<allow>ip</allow>
</ip-constraint>
<auth-constraint role-name='admin' />
</security-constraint>
<authenticator type="com.caucho.server.security.XmlAuthenticator">
<init>
<user name='admin' password='admin' roles='admin' />
<password-digest>none</password-digest>
</init>
</authenticator>
<login-config>
<auth-method>BASIC</auth-method>
<form-login-config> <form-login-page>/login.jsp</form-login-page>
<form-error-page>/error.jsp</form-error-page> </form-login-config>
</login-config>

浙公网安备 33010602011771号