Menu

#3 Authentication filter

First_release
open
Controller (5)
5
2009-03-25
2009-03-25
No

Check for every request if session has credentials and sends to login screen if not present. If current page is login - invalidate session (to logout simply move to login page).
Check is done via current page and rules (loaded from XML) like: page (user role, requests/mannaged beans). To permit access user must have specified user role and requests/mannaged beans loaded.

Discussion


Log in to post a comment.