Showing posts with label Spring Java config. Show all posts
Showing posts with label Spring Java config. Show all posts

Tuesday, August 5, 2014

JavaEE REST JAX-RS with Spring Security

Java EE REST JAX-RS with Spring Security


If you are using a JavaEE application server like Jboss, WildFly, GlassFish you get JAX-RS , JPA etc runtimes for 'free', if using Tomcat, Jetty etc, you might as well use the full Spring stack.
I tested on Jboss EAP 6.11, 7, WildFly and Glassfish.






/WEB-INF/applicationContext.xml Spring context file.
 <?xml version='1.0' encoding='UTF-8' ?>  
 <!-- was: <?xml version="1.0" encoding="UTF-8"?> -->  
 <beans xmlns="http://www.springframework.org/schema/beans"  
     xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"  
     xmlns:security="http://www.springframework.org/schema/security"  
     xmlns:p="http://www.springframework.org/schema/p"  
     xmlns:aop="http://www.springframework.org/schema/aop"  
     xmlns:tx="http://www.springframework.org/schema/tx"  
     xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-4.0.xsd  
     http://www.springframework.org/schema/aop http://www.springframework.org/schema/aop/spring-aop-4.0.xsd  
     http://www.springframework.org/schema/tx http://www.springframework.org/schema/tx/spring-tx-4.0.xsd  
     http://www.springframework.org/schema/security  
     http://www.springframework.org/schema/security/spring-security.xsd">  
   <!--bean id="propertyConfigurer"  
      class="org.springframework.beans.factory.config.PropertyPlaceholderConfigurer"  
      p:location="/WEB-INF/jdbc.properties" />  
   <bean id="dataSource"  
   class="org.springframework.jdbc.datasource.DriverManagerDataSource"  
   p:driverClassName="${jdbc.driverClassName}"  
   p:url="${jdbc.url}"  
   p:username="${jdbc.username}"  
   p:password="${jdbc.password}" /-->  
   <!-- ADD PERSISTENCE SUPPORT HERE (jpa, hibernate, etc) -->  
   <!--basic login security-->  
   <security:http>  
     <security:intercept-url pattern="/**" access="ROLE_USER" />  
     <security:form-login />  
     <security:logout />  
   </security:http>  
   <!--example from spring.io security reference-->  
   <security:authentication-manager>  
     <security:authentication-provider>  
       <security:user-service>  
         <security:user name="jimi" password="jimispassword" authorities="ROLE_USER, ROLE_ADMIN" />  
         <security:user name="bob" password="bobspassword" authorities="ROLE_USER" />  
       </security:user-service>  
     </security:authentication-provider>  
   </security:authentication-manager>  
   <!--secures all methods-->  
   <security:global-method-security secured-annotations="enabled" />  
 </beans>  



The web.xml


 <?xml version="1.0" encoding="UTF-8"?>  
 <web-app version="3.1" xmlns="http://xmlns.jcp.org/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://xmlns.jcp.org/xml/ns/javaee http://xmlns.jcp.org/xml/ns/javaee/web-app_3_1.xsd">  
   <context-param>  
     <param-name>contextConfigLocation</param-name>  
     <param-value>/WEB-INF/applicationContext.xml</param-value>  
   </context-param>  
   <listener>  
     <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class>  
   </listener>  
   <filter>  
    <filter-name>springSecurityFilterChain</filter-name>  
    <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>  
   </filter>  
   <filter-mapping>  
    <filter-name>springSecurityFilterChain</filter-name>  
    <url-pattern>/*</url-pattern>  
   </filter-mapping>  
   <session-config>  
     <session-timeout>  
       30  
     </session-timeout>  
   </session-config>  
   <welcome-file-list>  
     <welcome-file>redirect.jsp</welcome-file>  
   </welcome-file-list>  
 </web-app>  


The jax-rs path secured with annotation.


1:   @Secured("ROLE_ADMIN")  
2:    @GET  
3:    @Override  
4:    @Produces({ "application/json"})  
5:    public List<Customer> findAll() {  
6:      Authentication authentication = SecurityContextHolder.getContext().getAuthentication();  
7:      Object principal = authentication.getPrincipal();  
8:      if(principal instanceof User)  
9:        System.err.println("principal: " + ((User)principal).getUsername());  
10:      else  
11:        System.err.println("instance"+ principal.getClass().getTypeName());  
12:      System.err.println("roles :" + authentication.getAuthorities());  
13:      return super.findAll();  
14:    }  


Dependencies for spring security -


     <dependency>  
       <groupId>org.springframework</groupId>  
       <artifactId>spring-context</artifactId>  
       <version>4.0.6.RELEASE</version>  
     </dependency>  
     <dependency>  
       <groupId>org.springframework</groupId>  
       <artifactId>spring-context-support</artifactId>  
       <version>4.0.6.RELEASE</version>  
     </dependency>   
     <dependency>  
       <groupId>org.springframework.security</groupId>  
       <artifactId>spring-security-config</artifactId>  
       <version>3.2.4.RELEASE</version>  
     </dependency>  
     <dependency>  
       <groupId>org.springframework.security</groupId>  
       <artifactId>spring-security-core</artifactId>  
       <version>3.2.4.RELEASE</version>  
     </dependency>        
     <dependency>  
       <groupId>org.springframework.security</groupId>  
       <artifactId>spring-security-web</artifactId>  
       <version>3.2.4.RELEASE</version>  
     </dependency>  

Wednesday, March 19, 2014

JSF 2.2 Spring 4.X Configuration

JSF 2.2 with Spring 4.X


File : web.xml


<?xml version="1.0" encoding="UTF-8"?>
<web-app version="3.1" xmlns="http://xmlns.jcp.org/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://xmlns.jcp.org/xml/ns/javaee http://xmlns.jcp.org/xml/ns/javaee/web-app_3_1.xsd">
    <context-param>
        <param-name>javax.faces.PROJECT_STAGE</param-name>
        <param-value>Development</param-value>
    </context-param>  
    <context-param>
        <param-name>contextClass</param-name>
        <param-value>
            org.springframework.web.context.support.AnnotationConfigWebApplicationContext
        </param-value>
    </context-param>
    <!-- Configuration locations must consist of one or more comma- or space-delimited
        fully-qualified @Configuration classes. Fully-qualified packages may also be
        specified for component-scanning -->
    <context-param>
        <param-name>contextConfigLocation</param-name>
        <param-value>com.org.config.AppConfig</param-value>
    </context-param>
    <!-- Bootstrap the root application context as usual using ContextLoaderListener -->
    <context-param>
        <param-name>contextAttribute</param-name>
        <param-value>org.springframework.web.context.WebApplicationContext.ROOT</param-value>
    </context-param>
    <servlet>
        <servlet-name>Faces Servlet</servlet-name>
        <servlet-class>javax.faces.webapp.FacesServlet</servlet-class>
        <load-on-startup>1</load-on-startup>
    </servlet>
    <servlet>
        <servlet-name>AppUserServlet</servlet-name>
        <servlet-class>com.org.servlet.AppUserServlet</servlet-class>
    </servlet>
    <servlet-mapping>
        <servlet-name>Faces Servlet</servlet-name>
        <url-pattern>/faces/*</url-pattern>
    </servlet-mapping>
    <servlet-mapping>
        <servlet-name>AppUserServlet</servlet-name>
        <url-pattern>/AppUserServlet</url-pattern>
    </servlet-mapping>
    <session-config>
        <session-timeout>
            30
        </session-timeout>
    </session-config>
    <welcome-file-list>
        <welcome-file>faces/index.xhtml</welcome-file>
    </welcome-file-list>

</web-app>




Initialize Web Config


import org.springframework.security.web.context.*;
public class SecurityWebApplicationInitializer
      extends AbstractSecurityWebApplicationInitializer {
    public SecurityWebApplicationInitializer() {
        super(WebSecurityConfig.class);
    }
}






import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.builders.WebSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
@Configuration
@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
 @Override
 protected void configure(AuthenticationManagerBuilder authManagerBuilder) throws Exception {
  authManagerBuilder
   .inMemoryAuthentication().withUser("test").password("test").roles("ADMIN");

    }
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
                .anyRequest().authenticated()
                .and()
            .formLogin()
                .loginPage("/faces/login.xhtml")
                .permitAll();
    }
    //http://www.petrikainulainen.net/programming/spring-framework/adding-social-sign-in-to-a-spring-mvc-web-application-configuration/
    @Override
    public void configure(WebSecurity web) throws Exception {
        web
                //Spring Security ignores request to static resources such as CSS or JS files.
                .ignoring()
                    .antMatchers("/appContextRoot/faces/javax.faces.resource/**");
    }
             
}




Get AppContext from FacesContext;


ApplicationContext ctx = org.springframework.web.jsf.FacesContextUtils.getWebApplicationContext(FacesContext.getCurrentInstance());