Uploaded image for project: 'WildFly'
  1. WildFly
  2. WFLY-1113

JBoss AS 7 doesn't appear to support container-managed security via web.xml and jboss-web.xml

    XMLWordPrintable

Details

    • Feature Request
    • Resolution: Obsolete
    • Major
    • 8.0.0.Alpha1
    • None
    • Documentation
    • None
    • Documentation (Ref Guide, User Guide, etc.)

    Description

      There's no documentation for container-managed security in JBoss AS 7, and the schema for the main jboss config files and jboss-web.xml don't suggest any configuration mechanisms for JAAS realms, principal-to-user/group mappings, etc.

      This is a significant limitation for apps porting from Glassfish 3, which expect to be able to access the current security principal from JNDI or inject it, and expect to be able to declare container-controlled access to particular URLs and different HTTP methods in web.xml.

      Documenting this limitation in AS 7.0.0 would be a big improvement and would save porting time and hassle. Implementing support in a future version would, of course, be ideal.

      Attachments

        Activity

          People

            darran.lofthouse@redhat.com Darran Lofthouse
            ringerc_jira Craig Ringer (Inactive)
            Votes:
            1 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: