Repository: cxf-fediz Updated Branches: refs/heads/master f49b28e67 -> 31101469a
http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/simpleWebapp/src/main/resources/logging.properties ---------------------------------------------------------------------- diff --git a/systests/webapps/simpleWebapp/src/main/resources/logging.properties b/systests/webapps/simpleWebapp/src/main/resources/logging.properties new file mode 100644 index 0000000..c185d61 --- /dev/null +++ b/systests/webapps/simpleWebapp/src/main/resources/logging.properties @@ -0,0 +1,52 @@ +############################################################ +# Default Logging Configuration File +# +# You can use a different file by specifying a filename +# with the java.util.logging.config.file system property. +# For example java -Djava.util.logging.config.file=myfile +############################################################ + +############################################################ +# Global properties +############################################################ + +# "handlers" specifies a comma separated list of log Handler +# classes. These handlers will be installed during VM startup. +# Note that these classes must be on the system classpath. +# By default we only configure a ConsoleHandler, which will only +# show messages at the WARNING and above levels. +handlers= java.util.logging.ConsoleHandler +#handlers= java.util.logging.FileHandler, java.util.logging.ConsoleHandler + +# Default global logging level. +# This specifies which kinds of events are logged across +# all loggers. For any given facility this global level +# can be overridden by a facility specific level +# Note that the ConsoleHandler also has a separate level +# setting to limit messages printed to the console. +.level= INFO + +############################################################ +# Handler specific properties. +# Describes specific configuration info for Handlers. +############################################################ + +# default file output is in user's home directory. +java.util.logging.FileHandler.pattern = %h/java%u.log +java.util.logging.FileHandler.limit = 50000 +java.util.logging.FileHandler.count = 1 +java.util.logging.FileHandler.formatter = java.util.logging.XMLFormatter + +# Limit the message that are printed on the console to WARNING and above. +java.util.logging.ConsoleHandler.level = INFO +java.util.logging.ConsoleHandler.formatter = java.util.logging.SimpleFormatter + + +############################################################ +# Facility specific properties. +# Provides extra control for each logger. +############################################################ + +# For example, set the com.xyz.foo logger to only log SEVERE +# messages: +#com.xyz.foo.level = SEVERE http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/simpleWebapp/src/main/webapp/META-INF/context.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/simpleWebapp/src/main/webapp/META-INF/context.xml b/systests/webapps/simpleWebapp/src/main/webapp/META-INF/context.xml new file mode 100644 index 0000000..7fc734a --- /dev/null +++ b/systests/webapps/simpleWebapp/src/main/webapp/META-INF/context.xml @@ -0,0 +1,3 @@ +<Context> + <Valve className="org.apache.cxf.fediz.tomcat.FederationAuthenticator" configFile="conf/fediz_config.xml" /> +</Context> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/simpleWebapp/src/main/webapp/WEB-INF/web.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/simpleWebapp/src/main/webapp/WEB-INF/web.xml b/systests/webapps/simpleWebapp/src/main/webapp/WEB-INF/web.xml new file mode 100644 index 0000000..e96423f --- /dev/null +++ b/systests/webapps/simpleWebapp/src/main/webapp/WEB-INF/web.xml @@ -0,0 +1,105 @@ +<web-app xmlns="http://java.sun.com/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xsi:schemaLocation="http://java.sun.com/xml/ns/javaee + http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd" + version="3.0" metadata-complete="true"> + + <description>WS Federation Systests Example</description> + <display-name>WS Federation Systests Example</display-name> + + <!-- Optional: Cache the security token in Thread Local Storage --> + <filter> + <filter-name>FederationFilter</filter-name> + <filter-class>org.apache.cxf.fediz.core.servlet.FederationFilter</filter-class> + </filter> + + <filter-mapping> + <filter-name>FederationFilter</filter-name> + <url-pattern>/secure/*</url-pattern> + </filter-mapping> + + <servlet> + <servlet-name>FederationServlet</servlet-name> + <servlet-class>org.apache.cxf.fediz.example.FederationServlet</servlet-class> + </servlet> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/admin/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/user/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/manager/fedservlet</url-pattern> + </servlet-mapping> + + <security-role> + <role-name>Manager</role-name> + </security-role> + <security-role> + <role-name>User</role-name> + </security-role> + <security-role> + <role-name>Admin</role-name> + </security-role> + <security-role> + <role-name>Authenticated</role-name> + </security-role> + + <security-constraint> + <web-resource-collection> + <web-resource-name>Protected Area</web-resource-name> + <url-pattern>/secure/*</url-pattern> + </web-resource-collection> + <auth-constraint> + <role-name>*</role-name> + </auth-constraint> + </security-constraint> + + <security-constraint> + <web-resource-collection> + <web-resource-name>Protected Admin Area</web-resource-name> + <url-pattern>/secure/admin/*</url-pattern> + </web-resource-collection> + <auth-constraint> + <role-name>Admin</role-name> + </auth-constraint> + </security-constraint> + + <security-constraint> + <web-resource-collection> + <web-resource-name>Protected Manager Area</web-resource-name> + <url-pattern>/secure/manager/*</url-pattern> + </web-resource-collection> + <auth-constraint> + <role-name>Manager</role-name> + </auth-constraint> + </security-constraint> + + <security-constraint> + <web-resource-collection> + <web-resource-name>Protected User Area</web-resource-name> + <url-pattern>/secure/user/*</url-pattern> + </web-resource-collection> + <auth-constraint> + <role-name>User</role-name> + <role-name>Admin</role-name> + <role-name>Manager</role-name> + </auth-constraint> + </security-constraint> + + <login-config> + <auth-method>WSFED</auth-method> + <realm-name>WSFED</realm-name> + </login-config> + +</web-app> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/simpleWebapp/src/main/webapp/index.html ---------------------------------------------------------------------- diff --git a/systests/webapps/simpleWebapp/src/main/webapp/index.html b/systests/webapps/simpleWebapp/src/main/webapp/index.html new file mode 100644 index 0000000..a9dbdaa --- /dev/null +++ b/systests/webapps/simpleWebapp/src/main/webapp/index.html @@ -0,0 +1,25 @@ +<!-- + Licensed to the Apache Software Foundation (ASF) under one or more + contributor license agreements. See the NOTICE file distributed with + this work for additional information regarding copyright ownership. + The ASF licenses this file to You under the Apache License, Version 2.0 + (the "License"); you may not use this file except in compliance with + the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +--> +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> +<HTML><HEAD><TITLE>WS Federation Tomcat Examples</TITLE> +<META http-equiv=Content-Type content="text/html"> +</HEAD> +<BODY> +<P> +<H3>Hello World</H3> +<P></P> +</BODY></HTML> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/simpleWebapp/src/main/webapp/secure/test.html ---------------------------------------------------------------------- diff --git a/systests/webapps/simpleWebapp/src/main/webapp/secure/test.html b/systests/webapps/simpleWebapp/src/main/webapp/secure/test.html new file mode 100644 index 0000000..9cf7366 --- /dev/null +++ b/systests/webapps/simpleWebapp/src/main/webapp/secure/test.html @@ -0,0 +1,25 @@ +<!-- + Licensed to the Apache Software Foundation (ASF) under one or more + contributor license agreements. See the NOTICE file distributed with + this work for additional information regarding copyright ownership. + The ASF licenses this file to You under the Apache License, Version 2.0 + (the "License"); you may not use this file except in compliance with + the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +--> +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> +<HTML><HEAD><TITLE>WS Federation Tomcat Examples</TITLE> +<META http-equiv=Content-Type content="text/html"> +</HEAD> +<BODY> +<P> +<H3>Secure Test</H3> +<P></P> +</BODY></HTML> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/spring2Webapp/pom.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/spring2Webapp/pom.xml b/systests/webapps/spring2Webapp/pom.xml new file mode 100644 index 0000000..8f40f2c --- /dev/null +++ b/systests/webapps/spring2Webapp/pom.xml @@ -0,0 +1,135 @@ +<?xml version="1.0" encoding="UTF-8"?> +<!-- + Licensed to the Apache Software Foundation (ASF) under one + or more contributor license agreements. See the NOTICE file + distributed with this work for additional information + regarding copyright ownership. The ASF licenses this file + to you under the Apache License, Version 2.0 (the + "License"); you may not use this file except in compliance + with the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, + software distributed under the License is distributed on an + "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + KIND, either express or implied. See the License for the + specific language governing permissions and limitations + under the License. +--> +<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"> + <modelVersion>4.0.0</modelVersion> + <parent> + <groupId>org.apache.cxf.fediz.systests</groupId> + <artifactId>fediz-systests-webapps</artifactId> + <version>1.2.0-SNAPSHOT</version> + <relativePath>../pom.xml</relativePath> + </parent> + <groupId>org.apache.cxf.fediz.systests.webapps</groupId> + <artifactId>fediz-systests-webapps-spring2</artifactId> + <name>Apache Fediz Systests Spring2 Webapp</name> + <packaging>war</packaging> + + <properties> + <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> + <spring.security.version>2.0.8.RELEASE</spring.security.version> + </properties> + + <dependencyManagement> + <dependencies> + <dependency> + <groupId>org.springframework</groupId> + <artifactId>spring-web</artifactId> + <version>${spring.version}</version> + </dependency> + <dependency> + <groupId>org.springframework</groupId> + <artifactId>spring-context</artifactId> + <version>${spring.version}</version> + </dependency> + <dependency> + <groupId>org.springframework</groupId> + <artifactId>spring-aop</artifactId> + <version>${spring.version}</version> + </dependency> + <dependency> + <groupId>org.springframework</groupId> + <artifactId>spring-core</artifactId> + <version>${spring.version}</version> + </dependency> + </dependencies> + </dependencyManagement> + <dependencies> + <dependency> + <groupId>javax.servlet</groupId> + <artifactId>servlet-api</artifactId> + <version>${servlet.version}</version> + <scope>provided</scope> + </dependency> + <dependency> + <groupId>org.slf4j</groupId> + <artifactId>slf4j-log4j12</artifactId> + <version>${slf4j.version}</version> + </dependency> + <dependency> + <groupId>org.apache.cxf.fediz</groupId> + <artifactId>fediz-spring2</artifactId> + <version>${project.version}</version> + </dependency> + <dependency> + <groupId>org.springframework.security</groupId> + <artifactId>spring-security-core</artifactId> + <version>${spring.security.version}</version> + </dependency> + <dependency> + <groupId>org.springframework</groupId> + <artifactId>spring-web</artifactId> + <version>${spring.version}</version> + </dependency> + <dependency> + <groupId>org.apache.commons</groupId> + <artifactId>commons-lang3</artifactId> + <version>${commons.lang.version}</version> + </dependency> + <dependency> + <groupId>log4j</groupId> + <artifactId>log4j</artifactId> + <version>${log4j.version}</version> + <exclusions> + <exclusion> + <groupId>javax.mail</groupId> + <artifactId>mail</artifactId> + </exclusion> + <exclusion> + <groupId>javax.jms</groupId> + <artifactId>jms</artifactId> + </exclusion> + <exclusion> + <groupId>com.sun.jdmk</groupId> + <artifactId>jmxtools</artifactId> + </exclusion> + <exclusion> + <groupId>com.sun.jmx</groupId> + <artifactId>jmxri</artifactId> + </exclusion> + </exclusions> + </dependency> + </dependencies> + <build> + <plugins> + <plugin><!--for mvn tomcat:deploy/:undeploy/:redeploy --> + <groupId>org.codehaus.mojo</groupId> + <artifactId>tomcat-maven-plugin</artifactId> + <version>1.1</version> + <configuration> + <server>myTomcat</server> + <url>http://localhost:8080/manager/text</url> + <path>/${project.build.finalName}</path> + </configuration> + </plugin> + </plugins> + <!-- Name of the generated WAR file --> + <finalName>fedizhelloworld</finalName> + </build> + +</project> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/spring2Webapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java ---------------------------------------------------------------------- diff --git a/systests/webapps/spring2Webapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java b/systests/webapps/spring2Webapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java new file mode 100644 index 0000000..5d90f9c --- /dev/null +++ b/systests/webapps/spring2Webapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java @@ -0,0 +1,108 @@ +/** + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ + +package org.apache.cxf.fediz.example; + +import java.io.IOException; +import java.io.PrintWriter; +import java.security.Principal; +import java.util.Arrays; +import java.util.List; + +import javax.servlet.ServletException; +import javax.servlet.http.HttpServlet; +import javax.servlet.http.HttpServletRequest; +import javax.servlet.http.HttpServletResponse; + +import org.w3c.dom.Element; + +import org.apache.cxf.fediz.core.Claim; +import org.apache.cxf.fediz.core.ClaimCollection; +import org.apache.cxf.fediz.core.SecurityTokenThreadLocal; +import org.apache.cxf.fediz.spring.authentication.FederationAuthenticationToken; + +import org.springframework.security.Authentication; +import org.springframework.security.GrantedAuthority; +import org.springframework.security.context.SecurityContextHolder; + +public class FederationServlet extends HttpServlet { + + /** + * + */ + private static final long serialVersionUID = -9019993850246851112L; + + public void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, + IOException { + + response.setContentType("text/html"); + PrintWriter out = response.getWriter(); + + out.println("<html>"); + out.println("<head><title>WS Federation Systests Spring Examples</title></head>"); + out.println("<body>"); + out.println("<p>Request url: " + request.getRequestURL().toString() + "</p>"); + + out.print("<p>userPrincipal="); + Principal p = request.getUserPrincipal(); + if (p != null) { + out.print(p.getName()); + } + out.println("</p>"); + + // Access Spring security context + Authentication auth = SecurityContextHolder.getContext().getAuthentication(); + + if (auth instanceof FederationAuthenticationToken) { + FederationAuthenticationToken fedToken = (FederationAuthenticationToken)auth; + List<String> roleListToCheck = Arrays.asList("Admin", "Manager", "User", "Authenticated"); + + for (String item : roleListToCheck) { + boolean found = false; + for (GrantedAuthority ga : fedToken.getAuthorities()) { + if (ga.getAuthority().toLowerCase().indexOf(item.toLowerCase()) > -1) { + found = true; + break; + } + } + out.println("<p>role:" + item + "=" + (found ? "true" : "false") + "</p>"); + } + + ClaimCollection claims = fedToken.getClaims(); + for (Claim c : claims) { + out.println("<p>" + c.getClaimType().toString() + "=" + c.getValue() + "</p>"); + } + + Element el = fedToken.getLoginToken(); + if (el != null) { + out.println("loginToken=FOUND{FedizPrincipal}<p>"); + } + + el = SecurityTokenThreadLocal.getToken(); + if (el != null) { + out.println("loginToken=FOUND{SecurityTokenThreadLocal}<p>"); + } + + } + + out.println("</body>"); + + } + +} http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/spring2Webapp/src/main/resources/log4j.properties ---------------------------------------------------------------------- diff --git a/systests/webapps/spring2Webapp/src/main/resources/log4j.properties b/systests/webapps/spring2Webapp/src/main/resources/log4j.properties new file mode 100644 index 0000000..6f4ce54 --- /dev/null +++ b/systests/webapps/spring2Webapp/src/main/resources/log4j.properties @@ -0,0 +1,16 @@ +# Set root category priority to INFO and its only appender to CONSOLE. +log4j.rootLogger=INFO, CONSOLE +log4j.logger.org.springframework=INFO, CONSOLE +log4j.additivity.org.springframework=false +log4j.logger.org.springframework.security=DEBUG, CONSOLE +log4j.additivity.org.springframework.security=false +log4j.logger.org.apache.cxf.fediz=DEBUG, CONSOLE +log4j.additivity.org.apache.cxf.fediz=false + +# CONSOLE is set to be a ConsoleAppender using a PatternLayout. +log4j.appender.CONSOLE=org.apache.log4j.ConsoleAppender +log4j.appender.CONSOLE.Threshold=DEBUG +log4j.appender.CONSOLE.layout=org.apache.log4j.PatternLayout +log4j.appender.CONSOLE.layout.ConversionPattern=%d [%t] %-5p %c %x - %m%n + + http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/spring2Webapp/src/main/resources/logging.properties ---------------------------------------------------------------------- diff --git a/systests/webapps/spring2Webapp/src/main/resources/logging.properties b/systests/webapps/spring2Webapp/src/main/resources/logging.properties new file mode 100644 index 0000000..f5849dc --- /dev/null +++ b/systests/webapps/spring2Webapp/src/main/resources/logging.properties @@ -0,0 +1,53 @@ +############################################################ +# Default Logging Configuration File +# +# You can use a different file by specifying a filename +# with the java.util.logging.config.file system property. +# For example java -Djava.util.logging.config.file=myfile +############################################################ + +############################################################ +# Global properties +############################################################ + +# "handlers" specifies a comma separated list of log Handler +# classes. These handlers will be installed during VM startup. +# Note that these classes must be on the system classpath. +# By default we only configure a ConsoleHandler, which will only +# show messages at the WARNING and above levels. +handlers= java.util.logging.ConsoleHandler +#handlers= java.util.logging.FileHandler, java.util.logging.ConsoleHandler + +# Default global logging level. +# This specifies which kinds of events are logged across +# all loggers. For any given facility this global level +# can be overridden by a facility specific level +# Note that the ConsoleHandler also has a separate level +# setting to limit messages printed to the console. +.level= FINEST + +############################################################ +# Handler specific properties. +# Describes specific configuration info for Handlers. +############################################################ + +# default file output is in user's home directory. +java.util.logging.FileHandler.pattern = %h/java%u.log +java.util.logging.FileHandler.limit = 50000 +java.util.logging.FileHandler.count = 1 +java.util.logging.FileHandler.formatter = java.util.logging.XMLFormatter + +# Limit the message that are printed on the console to WARNING and above. +java.util.logging.ConsoleHandler.level = FINEST +java.util.logging.ConsoleHandler.formatter = java.util.logging.SimpleFormatter + + +############################################################ +# Facility specific properties. +# Provides extra control for each logger. +############################################################ + +# For example, set the com.xyz.foo logger to only log SEVERE +# messages: +#com.xyz.foo.level = SEVERE +#org.apache.cxf.fediz.level = FINEST http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/spring2Webapp/src/main/resources/ststrust.jks ---------------------------------------------------------------------- diff --git a/systests/webapps/spring2Webapp/src/main/resources/ststrust.jks b/systests/webapps/spring2Webapp/src/main/resources/ststrust.jks new file mode 100644 index 0000000..911945c Binary files /dev/null and b/systests/webapps/spring2Webapp/src/main/resources/ststrust.jks differ http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/spring2Webapp/src/main/webapp/WEB-INF/applicationContext-security.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/spring2Webapp/src/main/webapp/WEB-INF/applicationContext-security.xml b/systests/webapps/spring2Webapp/src/main/webapp/WEB-INF/applicationContext-security.xml new file mode 100644 index 0000000..3974a96 --- /dev/null +++ b/systests/webapps/spring2Webapp/src/main/webapp/WEB-INF/applicationContext-security.xml @@ -0,0 +1,71 @@ +<?xml version="1.0" encoding="UTF-8"?> + +<beans xmlns="http://www.springframework.org/schema/beans" + xmlns:sec="http://www.springframework.org/schema/security" + xmlns:p="http://www.springframework.org/schema/p" + xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xsi:schemaLocation="http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security-2.0.xsd +http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-2.0.xsd"> + + + <sec:http entry-point-ref="federationEntryPoint"> +<!-- + <sec:intercept-url pattern="/" access="permitAll"/> + <sec:intercept-url pattern="/fediz" access="permitAll"/> + <sec:intercept-url pattern="/index.html" access="permitAll"/> + <sec:intercept-url pattern="/secure/fedservlet" access="isAuthenticated()"/> +--> + <sec:intercept-url pattern="/FederationMetadata/**" access="IS_AUTHENTICATED_FULLY"/> + <sec:intercept-url pattern="/secure/fedservlet" access="IS_AUTHENTICATED_FULLY"/> + <sec:intercept-url pattern="/secure/manager/**" access="ROLE_MANAGER"/> + <sec:intercept-url pattern="/secure/admin/**" access="ROLE_ADMIN"/> + <sec:intercept-url pattern="/secure/user/**" access="ROLE_USER,ROLE_ADMIN,ROLE_MANAGER"/> + <!--<sec:custom-filter ref="federationFilter" after="BASIC_AUTH_FILTER" />--> + <!--<sec:session-management session-authentication-strategy-ref="sas"/>--> + </sec:http> + + + <sec:authentication-manager alias="authManager"/> + + <bean id="fedizConfig" class="org.apache.cxf.fediz.spring.FederationConfigImpl" init-method="init" + p:configFile="file:./target/test-classes/fediz_config.xml" p:contextName="/fedizhelloworld_spring2" /> + + <bean id="federationEntryPoint" + class="org.apache.cxf.fediz.spring.web.FederationAuthenticationEntryPoint" + p:federationConfig-ref="fedizConfig" /> + +<!-- Works without org.springframework.security.web.authentication.session.SessionFixationProtectionStrategy as well --> +<!-- + <bean id="federationFilter" + class="org.apache.cxf.fediz.spring.web.FederationAuthenticationFilter" + p:authenticationManager-ref="authManager" p:sessionAuthenticationStrategy-ref="sas"> + + <property name="authenticationFailureHandler"> + <bean class="org.springframework.security.web.authentication.SimpleUrlAuthenticationFailureHandler" /> + </property> + </bean> + --> + + <bean id="federationFilter" + class="org.apache.cxf.fediz.spring.web.FederationAuthenticationFilter" + p:authenticationManager-ref="authManager" p:defaultTargetUrl="/whatever"> + <sec:custom-filter after="BASIC_PROCESSING_FILTER"/> + <!-- + <property name="authenticationFailureHandler"> + <bean class="org.springframework.security.web.authentication.SimpleUrlAuthenticationFailureHandler" /> + </property> + --> + </bean> + + <bean id="federationAuthProvider" class="org.apache.cxf.fediz.spring.authentication.FederationAuthenticationProvider" + p:federationConfig-ref="fedizConfig"> + <sec:custom-authentication-provider /> + <property name="authenticationUserDetailsService"> + <bean class="org.apache.cxf.fediz.spring.authentication.GrantedAuthoritiesUserDetailsFederationService"/> + </property> + </bean> +<!-- + <bean id="sas" class="org.springframework.security.web.authentication.session.SessionFixationProtectionStrategy" /> +--> +</beans> + http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/spring2Webapp/src/main/webapp/WEB-INF/web.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/spring2Webapp/src/main/webapp/WEB-INF/web.xml b/systests/webapps/spring2Webapp/src/main/webapp/WEB-INF/web.xml new file mode 100644 index 0000000..996e5aa --- /dev/null +++ b/systests/webapps/spring2Webapp/src/main/webapp/WEB-INF/web.xml @@ -0,0 +1,76 @@ +<web-app xmlns="http://java.sun.com/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xsi:schemaLocation="http://java.sun.com/xml/ns/javaee + http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd" + version="3.0" metadata-complete="true"> + + <description>WS Federation Spring Example</description> + <display-name>WS Federation Spring Example</display-name> + + <filter> + <filter-name>springSecurityFilterChain</filter-name> + <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class> + </filter> + + <!-- Optional: Cache the security token in Thread Local Storage --> + <filter> + <filter-name>FederationFilter</filter-name> + <filter-class>org.apache.cxf.fediz.core.servlet.FederationFilter</filter-class> + </filter> + + <filter-mapping> + <filter-name>springSecurityFilterChain</filter-name> + <url-pattern>/*</url-pattern> + </filter-mapping> + + <filter-mapping> + <filter-name>FederationFilter</filter-name> + <url-pattern>/secure/*</url-pattern> + </filter-mapping> + + + <!-- + - Location of the XML file that defines the root application context + - Applied by ContextLoaderListener. + --> + <context-param> + <param-name>contextConfigLocation</param-name> + <param-value> + /WEB-INF/applicationContext-security.xml + </param-value> + </context-param> + + <!-- + - Loads the root application context of this web app at startup. + - The application context is then available via + - WebApplicationContextUtils.getWebApplicationContext(servletContext). + --> + <listener> + <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class> + </listener> + + <servlet> + <servlet-name>FederationServlet</servlet-name> + <servlet-class>org.apache.cxf.fediz.example.FederationServlet</servlet-class> + </servlet> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/admin/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/user/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/manager/fedservlet</url-pattern> + </servlet-mapping> + +</web-app> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/spring2Webapp/src/main/webapp/index.html ---------------------------------------------------------------------- diff --git a/systests/webapps/spring2Webapp/src/main/webapp/index.html b/systests/webapps/spring2Webapp/src/main/webapp/index.html new file mode 100644 index 0000000..a9dbdaa --- /dev/null +++ b/systests/webapps/spring2Webapp/src/main/webapp/index.html @@ -0,0 +1,25 @@ +<!-- + Licensed to the Apache Software Foundation (ASF) under one or more + contributor license agreements. See the NOTICE file distributed with + this work for additional information regarding copyright ownership. + The ASF licenses this file to You under the Apache License, Version 2.0 + (the "License"); you may not use this file except in compliance with + the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +--> +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> +<HTML><HEAD><TITLE>WS Federation Tomcat Examples</TITLE> +<META http-equiv=Content-Type content="text/html"> +</HEAD> +<BODY> +<P> +<H3>Hello World</H3> +<P></P> +</BODY></HTML> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/spring2Webapp/src/main/webapp/secure/test.html ---------------------------------------------------------------------- diff --git a/systests/webapps/spring2Webapp/src/main/webapp/secure/test.html b/systests/webapps/spring2Webapp/src/main/webapp/secure/test.html new file mode 100644 index 0000000..9cf7366 --- /dev/null +++ b/systests/webapps/spring2Webapp/src/main/webapp/secure/test.html @@ -0,0 +1,25 @@ +<!-- + Licensed to the Apache Software Foundation (ASF) under one or more + contributor license agreements. See the NOTICE file distributed with + this work for additional information regarding copyright ownership. + The ASF licenses this file to You under the Apache License, Version 2.0 + (the "License"); you may not use this file except in compliance with + the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +--> +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> +<HTML><HEAD><TITLE>WS Federation Tomcat Examples</TITLE> +<META http-equiv=Content-Type content="text/html"> +</HEAD> +<BODY> +<P> +<H3>Secure Test</H3> +<P></P> +</BODY></HTML> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springPreauthWebapp/pom.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/springPreauthWebapp/pom.xml b/systests/webapps/springPreauthWebapp/pom.xml new file mode 100644 index 0000000..aaa7992 --- /dev/null +++ b/systests/webapps/springPreauthWebapp/pom.xml @@ -0,0 +1,125 @@ +<?xml version="1.0" encoding="UTF-8"?> +<!-- + Licensed to the Apache Software Foundation (ASF) under one + or more contributor license agreements. See the NOTICE file + distributed with this work for additional information + regarding copyright ownership. The ASF licenses this file + to you under the Apache License, Version 2.0 (the + "License"); you may not use this file except in compliance + with the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, + software distributed under the License is distributed on an + "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + KIND, either express or implied. See the License for the + specific language governing permissions and limitations + under the License. +--> +<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"> + + <modelVersion>4.0.0</modelVersion> + <parent> + <groupId>org.apache.cxf.fediz.systests</groupId> + <artifactId>fediz-systests-webapps</artifactId> + <version>1.2.0-SNAPSHOT</version> + <relativePath>../pom.xml</relativePath> + </parent> + <groupId>org.apache.cxf.fediz.systests.webapps</groupId> + <artifactId>fediz-systests-webapps-springPreauth</artifactId> + <name>Apache Fediz Systests SpringWebapp (Pre-Authentication)</name> + <packaging>war</packaging> + + <properties> + <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> + </properties> + + <dependencies> + <dependency> + <groupId>commons-logging</groupId> + <artifactId>commons-logging</artifactId> + <version>${commons.logging.version}</version> + <scope>provided</scope> + </dependency> + <dependency> + <groupId>javax.servlet</groupId> + <artifactId>servlet-api</artifactId> + <version>${servlet.version}</version> + <scope>provided</scope> + </dependency> + <!-- Required to cast Principal to FederationPrincipal --> + <dependency> + <groupId>org.apache.cxf.fediz</groupId> + <artifactId>fediz-core</artifactId> + <version>${project.version}</version> + <scope>provided</scope> + </dependency> + <dependency> + <groupId>org.apache.cxf.fediz</groupId> + <artifactId>fediz-spring</artifactId> + <version>${project.version}</version> + </dependency> + <dependency> + <groupId>org.apache.commons</groupId> + <artifactId>commons-lang3</artifactId> + <version>${commons.lang.version}</version> + </dependency> + <dependency> + <groupId>org.springframework.security</groupId> + <artifactId>spring-security-web</artifactId> + <version>${spring.security.version}</version> + </dependency> + <dependency> + <groupId>org.springframework.security</groupId> + <artifactId>spring-security-config</artifactId> + <version>${spring.security.version}</version> + </dependency> + <dependency> + <groupId>org.slf4j</groupId> + <artifactId>slf4j-log4j12</artifactId> + <version>${slf4j.version}</version> + </dependency> + <dependency> + <groupId>log4j</groupId> + <artifactId>log4j</artifactId> + <version>${log4j.version}</version> + <exclusions> + <exclusion> + <groupId>javax.mail</groupId> + <artifactId>mail</artifactId> + </exclusion> + <exclusion> + <groupId>javax.jms</groupId> + <artifactId>jms</artifactId> + </exclusion> + <exclusion> + <groupId>com.sun.jdmk</groupId> + <artifactId>jmxtools</artifactId> + </exclusion> + <exclusion> + <groupId>com.sun.jmx</groupId> + <artifactId>jmxri</artifactId> + </exclusion> + </exclusions> + </dependency> + </dependencies> + + <build> + <plugins> + <plugin><!--for mvn tomcat:deploy/:undeploy/:redeploy --> + <groupId>org.codehaus.mojo</groupId> + <artifactId>tomcat-maven-plugin</artifactId> + <version>1.1</version> + <configuration> + <server>myTomcat</server> + <url>http://localhost:8080/manager/text</url> + <path>/${project.build.finalName}</path> + </configuration> + </plugin> + </plugins> + <!-- Name of the generated WAR file --> + <finalName>fedizhelloworld</finalName> + </build> + +</project> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springPreauthWebapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java ---------------------------------------------------------------------- diff --git a/systests/webapps/springPreauthWebapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java b/systests/webapps/springPreauthWebapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java new file mode 100644 index 0000000..d23281c --- /dev/null +++ b/systests/webapps/springPreauthWebapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java @@ -0,0 +1,108 @@ +/** + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ + +package org.apache.cxf.fediz.example; + +import java.io.IOException; +import java.io.PrintWriter; +import java.security.Principal; +import java.util.Arrays; +import java.util.List; + +import javax.servlet.ServletException; +import javax.servlet.http.HttpServlet; +import javax.servlet.http.HttpServletRequest; +import javax.servlet.http.HttpServletResponse; + +import org.w3c.dom.Element; + +import org.apache.cxf.fediz.core.Claim; +import org.apache.cxf.fediz.core.ClaimCollection; +import org.apache.cxf.fediz.core.FedizPrincipal; +import org.apache.cxf.fediz.core.SecurityTokenThreadLocal; + +import org.springframework.security.core.Authentication; +import org.springframework.security.core.context.SecurityContextHolder; +import org.springframework.util.Assert; + +public class FederationServlet extends HttpServlet { + + /** + * + */ + private static final long serialVersionUID = -9019993850246851112L; + + public void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, + IOException { + + response.setContentType("text/html"); + PrintWriter out = response.getWriter(); + + out.println("<html>"); + out.println("<head><title>WS Federation Systests Spring Examples</title></head>"); + out.println("<body>"); + out.println("<p>Request url: " + request.getRequestURL().toString() + "</p>"); + + out.print("<p>userPrincipal="); + Principal p = request.getUserPrincipal(); + if (p != null) { + out.print(p.getName()); + } + out.println("</p>"); + + List<String> roleListToCheck = Arrays.asList("Admin", "Manager", "User", "Authenticated"); + for (String item : roleListToCheck) { + out.println("<p>role:" + item + "=" + ((request.isUserInRole(item)) ? "true" : "false") + "</p>"); + } + + if (p instanceof FedizPrincipal) { + FedizPrincipal fp = (FedizPrincipal)p; + + ClaimCollection claims = fp.getClaims(); + for (Claim c : claims) { + out.println("<p>" + c.getClaimType().toString() + "=" + c.getValue() + "</p>"); + } + + Element el = fp.getLoginToken(); + if (el != null) { + out.println("loginToken=FOUND{FedizPrincipal}<p>"); + } + + el = SecurityTokenThreadLocal.getToken(); + if (el != null) { + out.println("loginToken=FOUND{SecurityTokenThreadLocal}<p>"); + } + } + + out.println("</body>"); + + // Access Spring security context + Assert.notNull(SecurityContextHolder.getContext().getAuthentication(), + "SecurityContextHolder Authentication not null"); + + Authentication obj = SecurityContextHolder.getContext().getAuthentication(); + System.out.println("getCredentials: " + obj.getCredentials().toString()); + System.out.println("getDetails: " + obj.getDetails().toString()); + System.out.println("getName: " + obj.getName().toString()); + System.out.println("getAuthorities: " + obj.getAuthorities().toString()); + System.out.println("getPrincipal: " + obj.getPrincipal().toString()); + + } + +} http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springPreauthWebapp/src/main/resources/log4j.properties ---------------------------------------------------------------------- diff --git a/systests/webapps/springPreauthWebapp/src/main/resources/log4j.properties b/systests/webapps/springPreauthWebapp/src/main/resources/log4j.properties new file mode 100644 index 0000000..e2cc4b0 --- /dev/null +++ b/systests/webapps/springPreauthWebapp/src/main/resources/log4j.properties @@ -0,0 +1,20 @@ +# Set root category priority to INFO and its only appender to CONSOLE. +#log4j.rootLogger=INFO, CONSOLE +log4j.rootLogger=DEBUG, CONSOLE +#log4j.logger.org.springframework=INFO, CONSOLE +#log4j.logger.org.springframework.security=DEBUG, CONSOLE,LOGFILE +#log4j.logger.org.apache.cxf.fediz=DEBUG, CONSOLE,LOGFILE + +# CONSOLE is set to be a ConsoleAppender using a PatternLayout. +log4j.appender.CONSOLE=org.apache.log4j.ConsoleAppender +log4j.appender.CONSOLE.Threshold=DEBUG +log4j.appender.CONSOLE.layout=org.apache.log4j.PatternLayout +log4j.appender.CONSOLE.layout.ConversionPattern=%d [%t] %-5p %c %x - %m%n + +# LOGFILE is set to be a File appender using a PatternLayout. +log4j.appender.LOGFILE=org.apache.log4j.FileAppender +log4j.appender.LOGFILE.File=fedizhelloworld.log +log4j.appender.LOGFILE.Append=false +log4j.appender.LOGFILE.Threshold=DEBUG +log4j.appender.LOGFILE.layout=org.apache.log4j.PatternLayout +log4j.appender.LOGFILE.layout.ConversionPattern=%d [%t] %-5p %c %x - %m%n http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springPreauthWebapp/src/main/webapp/META-INF/context.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/springPreauthWebapp/src/main/webapp/META-INF/context.xml b/systests/webapps/springPreauthWebapp/src/main/webapp/META-INF/context.xml new file mode 100644 index 0000000..7fc734a --- /dev/null +++ b/systests/webapps/springPreauthWebapp/src/main/webapp/META-INF/context.xml @@ -0,0 +1,3 @@ +<Context> + <Valve className="org.apache.cxf.fediz.tomcat.FederationAuthenticator" configFile="conf/fediz_config.xml" /> +</Context> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springPreauthWebapp/src/main/webapp/WEB-INF/applicationContext-security.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/springPreauthWebapp/src/main/webapp/WEB-INF/applicationContext-security.xml b/systests/webapps/springPreauthWebapp/src/main/webapp/WEB-INF/applicationContext-security.xml new file mode 100644 index 0000000..2b05358 --- /dev/null +++ b/systests/webapps/springPreauthWebapp/src/main/webapp/WEB-INF/applicationContext-security.xml @@ -0,0 +1,98 @@ +<?xml version="1.0" encoding="UTF-8"?> + +<!-- + - Sample namespace-based configuration + - + --> + +<beans xmlns="http://www.springframework.org/schema/beans" + xmlns:sec="http://www.springframework.org/schema/security" + xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-3.0.xsd + http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security.xsd"> + + <bean id="filterChainProxy" class="org.springframework.security.web.FilterChainProxy"> + <sec:filter-chain-map path-type="ant"> + <sec:filter-chain pattern="/**" filters="sif,j2eePreAuthFilter,logoutFilter,etf,fsi"/> + </sec:filter-chain-map> + </bean> + + <bean id="sif" class="org.springframework.security.web.context.SecurityContextPersistenceFilter"/> + + <sec:authentication-manager alias="authenticationManager"> + <sec:authentication-provider ref='preAuthenticatedAuthenticationProvider'/> + </sec:authentication-manager> + + <bean id="preAuthenticatedAuthenticationProvider" class="org.springframework.security.web.authentication.preauth.PreAuthenticatedAuthenticationProvider"> + <property name="preAuthenticatedUserDetailsService" ref="preAuthenticatedUserDetailsService"/> + </bean> + + <!-- + <bean id="preAuthenticatedUserDetailsService" + class="org.springframework.security.web.authentication.preauth.PreAuthenticatedGrantedAuthoritiesUserDetailsService"/> + --> + <bean id="preAuthenticatedUserDetailsService" + class="org.apache.cxf.fediz.spring.preauth.PreAuthenticatedGrantedAuthoritiesUserDetailsFederationService"/> + + <!--<bean id="j2eePreAuthFilter" class="org.springframework.security.web.authentication.preauth.j2ee.J2eePreAuthenticatedProcessingFilter">--> + <bean id="j2eePreAuthFilter" class="org.apache.cxf.fediz.spring.preauth.FederationPreAuthenticatedProcessingFilter"> + <property name="authenticationManager" ref="authenticationManager"/> + <property name="authenticationDetailsSource"> + <bean class="org.springframework.security.web.authentication.preauth.j2ee.J2eeBasedPreAuthenticatedWebAuthenticationDetailsSource"> + <property name="mappableRolesRetriever"> + <bean class="org.springframework.security.web.authentication.preauth.j2ee.WebXmlMappableAttributesRetriever" /> + </property> + <property name="userRoles2GrantedAuthoritiesMapper"> + <bean class="org.springframework.security.core.authority.mapping.SimpleAttributes2GrantedAuthoritiesMapper"> + <property name="convertAttributeToUpperCase" value="true"/> + </bean> + </property> + </bean> + </property> + </bean> + + <bean id="preAuthenticatedProcessingFilterEntryPoint" + class="org.springframework.security.web.authentication.Http403ForbiddenEntryPoint"/> + + <bean id="logoutFilter" class="org.springframework.security.web.authentication.logout.LogoutFilter"> + <constructor-arg value="/"/> + <constructor-arg> + <list> + <bean class="org.springframework.security.web.authentication.logout.SecurityContextLogoutHandler"/> + </list> + </constructor-arg> + </bean> + + <bean id="servletContext" class="org.springframework.web.context.support.ServletContextFactoryBean"/> + + <bean id="etf" class="org.springframework.security.web.access.ExceptionTranslationFilter"> + <property name="authenticationEntryPoint" ref="preAuthenticatedProcessingFilterEntryPoint"/> + </bean> + + <bean id="httpRequestAccessDecisionManager" class="org.springframework.security.access.vote.AffirmativeBased"> + <property name="allowIfAllAbstainDecisions" value="false"/> + <property name="decisionVoters"> + <list> + <ref bean="roleVoter"/> + </list> + </property> + </bean> + + <bean id="fsi" class="org.springframework.security.web.access.intercept.FilterSecurityInterceptor"> + <property name="authenticationManager" ref="authenticationManager"/> + <property name="accessDecisionManager" ref="httpRequestAccessDecisionManager"/> + <property name="securityMetadataSource"> + <sec:filter-invocation-definition-source> + <sec:intercept-url pattern="/secure/manager/**" access="ROLE_MANAGER"/> + <sec:intercept-url pattern="/secure/admin/**" access="ROLE_ADMIN"/> + <sec:intercept-url pattern="/secure/user/**" access="ROLE_USER,ROLE_ADMIN,ROLE_MANAGER"/> + <sec:intercept-url pattern="/secure/fedservlet" access="ROLE_USER,ROLE_ADMIN,ROLE_MANAGER,ROLE_AUTHENTICATED"/> + </sec:filter-invocation-definition-source> + </property> + </bean> + + <bean id="roleVoter" class="org.springframework.security.access.vote.RoleVoter"/> + + <bean id="securityContextHolderAwareRequestFilter" class="org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter"/> + +</beans> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springPreauthWebapp/src/main/webapp/WEB-INF/web.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/springPreauthWebapp/src/main/webapp/WEB-INF/web.xml b/systests/webapps/springPreauthWebapp/src/main/webapp/WEB-INF/web.xml new file mode 100644 index 0000000..0149aac --- /dev/null +++ b/systests/webapps/springPreauthWebapp/src/main/webapp/WEB-INF/web.xml @@ -0,0 +1,107 @@ +<web-app xmlns="http://java.sun.com/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xsi:schemaLocation="http://java.sun.com/xml/ns/javaee + http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd" + version="3.0" metadata-complete="true"> + + <description> + WS Federation Spring Example + </description> + <display-name>WS Federation Spring Example</display-name> + + + + <!-- + - Location of the XML file that defines the root application context + - Applied by ContextLoaderListener. + --> + <context-param> + <param-name>contextConfigLocation</param-name> + <param-value> + /WEB-INF/applicationContext-security.xml + </param-value> + </context-param> + + <filter> + <filter-name>filterChainProxy</filter-name> + <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class> + </filter> + + <!-- Optional: Cache the security token in Thread Local Storage --> + <filter> + <filter-name>FederationFilter</filter-name> + <filter-class>org.apache.cxf.fediz.core.servlet.FederationFilter</filter-class> + </filter> + + <filter-mapping> + <filter-name>filterChainProxy</filter-name> + <url-pattern>/*</url-pattern> + </filter-mapping> + + <filter-mapping> + <filter-name>FederationFilter</filter-name> + <url-pattern>/secure/*</url-pattern> + </filter-mapping> + + <!-- + - Loads the root application context of this web app at startup. + - The application context is then available via + - WebApplicationContextUtils.getWebApplicationContext(servletContext). + --> + <listener> + <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class> + </listener> + + <servlet> + <servlet-name>FederationServlet</servlet-name> + <servlet-class>org.apache.cxf.fediz.example.FederationServlet</servlet-class> + </servlet> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/admin/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/user/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/manager/fedservlet</url-pattern> + </servlet-mapping> + + <security-role> + <role-name>Manager</role-name> + </security-role> + <security-role> + <role-name>User</role-name> + </security-role> + <security-role> + <role-name>Admin</role-name> + </security-role> + <security-role> + <role-name>Authenticated</role-name> + </security-role> + + <security-constraint> + <web-resource-collection> + <web-resource-name>Protected Area</web-resource-name> + <url-pattern>/secure/*</url-pattern> + </web-resource-collection> + <auth-constraint> + <role-name>*</role-name> + </auth-constraint> + </security-constraint> + + <login-config> + <auth-method>WSFED</auth-method> + <realm-name>WSFED</realm-name> + </login-config> + +</web-app> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springPreauthWebapp/src/main/webapp/index.html ---------------------------------------------------------------------- diff --git a/systests/webapps/springPreauthWebapp/src/main/webapp/index.html b/systests/webapps/springPreauthWebapp/src/main/webapp/index.html new file mode 100644 index 0000000..a9dbdaa --- /dev/null +++ b/systests/webapps/springPreauthWebapp/src/main/webapp/index.html @@ -0,0 +1,25 @@ +<!-- + Licensed to the Apache Software Foundation (ASF) under one or more + contributor license agreements. See the NOTICE file distributed with + this work for additional information regarding copyright ownership. + The ASF licenses this file to You under the Apache License, Version 2.0 + (the "License"); you may not use this file except in compliance with + the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +--> +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> +<HTML><HEAD><TITLE>WS Federation Tomcat Examples</TITLE> +<META http-equiv=Content-Type content="text/html"> +</HEAD> +<BODY> +<P> +<H3>Hello World</H3> +<P></P> +</BODY></HTML> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springPreauthWebapp/src/main/webapp/secure/test.html ---------------------------------------------------------------------- diff --git a/systests/webapps/springPreauthWebapp/src/main/webapp/secure/test.html b/systests/webapps/springPreauthWebapp/src/main/webapp/secure/test.html new file mode 100644 index 0000000..9cf7366 --- /dev/null +++ b/systests/webapps/springPreauthWebapp/src/main/webapp/secure/test.html @@ -0,0 +1,25 @@ +<!-- + Licensed to the Apache Software Foundation (ASF) under one or more + contributor license agreements. See the NOTICE file distributed with + this work for additional information regarding copyright ownership. + The ASF licenses this file to You under the Apache License, Version 2.0 + (the "License"); you may not use this file except in compliance with + the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +--> +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> +<HTML><HEAD><TITLE>WS Federation Tomcat Examples</TITLE> +<META http-equiv=Content-Type content="text/html"> +</HEAD> +<BODY> +<P> +<H3>Secure Test</H3> +<P></P> +</BODY></HTML> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springWebapp/pom.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/springWebapp/pom.xml b/systests/webapps/springWebapp/pom.xml new file mode 100644 index 0000000..ebf8337 --- /dev/null +++ b/systests/webapps/springWebapp/pom.xml @@ -0,0 +1,101 @@ +<?xml version="1.0" encoding="UTF-8"?> +<!-- + Licensed to the Apache Software Foundation (ASF) under one + or more contributor license agreements. See the NOTICE file + distributed with this work for additional information + regarding copyright ownership. The ASF licenses this file + to you under the Apache License, Version 2.0 (the + "License"); you may not use this file except in compliance + with the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, + software distributed under the License is distributed on an + "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + KIND, either express or implied. See the License for the + specific language governing permissions and limitations + under the License. +--> +<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"> + <modelVersion>4.0.0</modelVersion> + <parent> + <groupId>org.apache.cxf.fediz.systests</groupId> + <artifactId>fediz-systests-webapps</artifactId> + <version>1.2.0-SNAPSHOT</version> + <relativePath>../pom.xml</relativePath> + </parent> + <groupId>org.apache.cxf.fediz.systests.webapps</groupId> + <artifactId>fediz-systests-webapps-spring</artifactId> + <name>Apache Fediz Systests SpringWebapp</name> + <packaging>war</packaging> + + <properties> + <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> + </properties> + + <dependencies> + <dependency> + <groupId>javax.servlet</groupId> + <artifactId>servlet-api</artifactId> + <version>${servlet.version}</version> + <scope>provided</scope> + </dependency> + <dependency> + <groupId>org.slf4j</groupId> + <artifactId>slf4j-log4j12</artifactId> + <version>${slf4j.version}</version> + </dependency> + <dependency> + <groupId>org.apache.cxf.fediz</groupId> + <artifactId>fediz-spring</artifactId> + <version>${project.version}</version> + </dependency> + <dependency> + <groupId>org.apache.commons</groupId> + <artifactId>commons-lang3</artifactId> + <version>${commons.lang.version}</version> + </dependency> + <dependency> + <groupId>log4j</groupId> + <artifactId>log4j</artifactId> + <version>${log4j.version}</version> + <exclusions> + <exclusion> + <groupId>javax.mail</groupId> + <artifactId>mail</artifactId> + </exclusion> + <exclusion> + <groupId>javax.jms</groupId> + <artifactId>jms</artifactId> + </exclusion> + <exclusion> + <groupId>com.sun.jdmk</groupId> + <artifactId>jmxtools</artifactId> + </exclusion> + <exclusion> + <groupId>com.sun.jmx</groupId> + <artifactId>jmxri</artifactId> + </exclusion> + </exclusions> + </dependency> + </dependencies> + + <build> + <plugins> + <plugin><!--for mvn tomcat:deploy/:undeploy/:redeploy --> + <groupId>org.codehaus.mojo</groupId> + <artifactId>tomcat-maven-plugin</artifactId> + <version>1.1</version> + <configuration> + <server>myTomcat</server> + <url>http://localhost:8080/manager/text</url> + <path>/${project.build.finalName}</path> + </configuration> + </plugin> + </plugins> + <!-- Name of the generated WAR file --> + <finalName>fedizhelloworld</finalName> + </build> + +</project> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springWebapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java ---------------------------------------------------------------------- diff --git a/systests/webapps/springWebapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java b/systests/webapps/springWebapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java new file mode 100644 index 0000000..df0ce26 --- /dev/null +++ b/systests/webapps/springWebapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java @@ -0,0 +1,108 @@ +/** + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ + +package org.apache.cxf.fediz.example; + +import java.io.IOException; +import java.io.PrintWriter; +import java.security.Principal; +import java.util.Arrays; +import java.util.List; + +import javax.servlet.ServletException; +import javax.servlet.http.HttpServlet; +import javax.servlet.http.HttpServletRequest; +import javax.servlet.http.HttpServletResponse; + +import org.w3c.dom.Element; + +import org.apache.cxf.fediz.core.Claim; +import org.apache.cxf.fediz.core.ClaimCollection; +import org.apache.cxf.fediz.core.SecurityTokenThreadLocal; +import org.apache.cxf.fediz.spring.authentication.FederationAuthenticationToken; + +import org.springframework.security.core.Authentication; +import org.springframework.security.core.GrantedAuthority; +import org.springframework.security.core.context.SecurityContextHolder; + +public class FederationServlet extends HttpServlet { + + /** + * + */ + private static final long serialVersionUID = -9019993850246851112L; + + public void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, + IOException { + + response.setContentType("text/html"); + PrintWriter out = response.getWriter(); + + out.println("<html>"); + out.println("<head><title>WS Federation Systests Examples</title></head>"); + out.println("<body>"); + out.println("<p>Request url: " + request.getRequestURL().toString() + "</p>"); + + out.print("<p>userPrincipal="); + Principal p = request.getUserPrincipal(); + if (p != null) { + out.print(p.getName()); + } + out.println("</p>"); + + // Access Spring security context + Authentication auth = SecurityContextHolder.getContext().getAuthentication(); + + if (auth instanceof FederationAuthenticationToken) { + FederationAuthenticationToken fedToken = (FederationAuthenticationToken)auth; + List<String> roleListToCheck = Arrays.asList("Admin", "Manager", "User", "Authenticated"); + + for (String item : roleListToCheck) { + boolean found = false; + for (GrantedAuthority ga : fedToken.getAuthorities()) { + if (ga.getAuthority().toLowerCase().indexOf(item.toLowerCase()) > -1) { + found = true; + break; + } + } + out.println("<p>role:" + item + "=" + (found ? "true" : "false") + "</p>"); + } + + ClaimCollection claims = fedToken.getClaims(); + for (Claim c : claims) { + out.println("<p>" + c.getClaimType().toString() + "=" + c.getValue() + "</p>"); + } + + Element el = fedToken.getLoginToken(); + if (el != null) { + out.println("loginToken=FOUND{FedizPrincipal}<p>"); + } + + el = SecurityTokenThreadLocal.getToken(); + if (el != null) { + out.println("loginToken=FOUND{SecurityTokenThreadLocal}<p>"); + } + + } + + out.println("</body>"); + + } + +} http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springWebapp/src/main/resources/log4j.properties ---------------------------------------------------------------------- diff --git a/systests/webapps/springWebapp/src/main/resources/log4j.properties b/systests/webapps/springWebapp/src/main/resources/log4j.properties new file mode 100644 index 0000000..32d28b6 --- /dev/null +++ b/systests/webapps/springWebapp/src/main/resources/log4j.properties @@ -0,0 +1,16 @@ +# Set root category priority to INFO and its only appender to CONSOLE. +log4j.rootLogger=INFO, CONSOLE +log4j.logger.org.springframework=INFO, CONSOLE +log4j.additivity.org.springframework=false +log4j.logger.org.springframework.security=DEBUG, CONSOLE +log4j.additivity.org.springframework.security=false +log4j.logger.org.apache.cxf.fediz=DEBUG, CONSOLE +log4j.additivity.org.apache.cxf.fediz=false + +# CONSOLE is set to be a ConsoleAppender using a PatternLayout. +log4j.appender.CONSOLE=org.apache.log4j.ConsoleAppender +log4j.appender.CONSOLE.Threshold=INFO +log4j.appender.CONSOLE.layout=org.apache.log4j.PatternLayout +log4j.appender.CONSOLE.layout.ConversionPattern=%d [%t] %-5p %c %x - %m%n + + http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springWebapp/src/main/resources/logging.properties ---------------------------------------------------------------------- diff --git a/systests/webapps/springWebapp/src/main/resources/logging.properties b/systests/webapps/springWebapp/src/main/resources/logging.properties new file mode 100644 index 0000000..f5849dc --- /dev/null +++ b/systests/webapps/springWebapp/src/main/resources/logging.properties @@ -0,0 +1,53 @@ +############################################################ +# Default Logging Configuration File +# +# You can use a different file by specifying a filename +# with the java.util.logging.config.file system property. +# For example java -Djava.util.logging.config.file=myfile +############################################################ + +############################################################ +# Global properties +############################################################ + +# "handlers" specifies a comma separated list of log Handler +# classes. These handlers will be installed during VM startup. +# Note that these classes must be on the system classpath. +# By default we only configure a ConsoleHandler, which will only +# show messages at the WARNING and above levels. +handlers= java.util.logging.ConsoleHandler +#handlers= java.util.logging.FileHandler, java.util.logging.ConsoleHandler + +# Default global logging level. +# This specifies which kinds of events are logged across +# all loggers. For any given facility this global level +# can be overridden by a facility specific level +# Note that the ConsoleHandler also has a separate level +# setting to limit messages printed to the console. +.level= FINEST + +############################################################ +# Handler specific properties. +# Describes specific configuration info for Handlers. +############################################################ + +# default file output is in user's home directory. +java.util.logging.FileHandler.pattern = %h/java%u.log +java.util.logging.FileHandler.limit = 50000 +java.util.logging.FileHandler.count = 1 +java.util.logging.FileHandler.formatter = java.util.logging.XMLFormatter + +# Limit the message that are printed on the console to WARNING and above. +java.util.logging.ConsoleHandler.level = FINEST +java.util.logging.ConsoleHandler.formatter = java.util.logging.SimpleFormatter + + +############################################################ +# Facility specific properties. +# Provides extra control for each logger. +############################################################ + +# For example, set the com.xyz.foo logger to only log SEVERE +# messages: +#com.xyz.foo.level = SEVERE +#org.apache.cxf.fediz.level = FINEST http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springWebapp/src/main/resources/ststrust.jks ---------------------------------------------------------------------- diff --git a/systests/webapps/springWebapp/src/main/resources/ststrust.jks b/systests/webapps/springWebapp/src/main/resources/ststrust.jks new file mode 100644 index 0000000..911945c Binary files /dev/null and b/systests/webapps/springWebapp/src/main/resources/ststrust.jks differ http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springWebapp/src/main/webapp/WEB-INF/applicationContext-security.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/springWebapp/src/main/webapp/WEB-INF/applicationContext-security.xml b/systests/webapps/springWebapp/src/main/webapp/WEB-INF/applicationContext-security.xml new file mode 100644 index 0000000..b2c1a08 --- /dev/null +++ b/systests/webapps/springWebapp/src/main/webapp/WEB-INF/applicationContext-security.xml @@ -0,0 +1,94 @@ +<?xml version="1.0" encoding="UTF-8"?> + +<beans xmlns="http://www.springframework.org/schema/beans" + xmlns:sec="http://www.springframework.org/schema/security" + xmlns:p="http://www.springframework.org/schema/p" + xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xmlns:context="http://www.springframework.org/schema/context" + xmlns:util="http://www.springframework.org/schema/util" + xsi:schemaLocation="http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security-3.1.xsd +http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-3.0.xsd +http://www.springframework.org/schema/util http://www.springframework.org/schema/util/spring-util-3.0.xsd +http://www.springframework.org/schema/context http://www.springframework.org/schema/context/spring-context-3.0.xsd"> + + <!-- DIABLE in production as it might log confidential information about the user --> + <sec:debug /> + + <sec:http entry-point-ref="federationEntryPoint" use-expressions="true"> + <sec:intercept-url pattern="/" access="permitAll"/> + <sec:intercept-url pattern="/fediz" access="permitAll"/> + <sec:intercept-url pattern="/index.html" access="permitAll"/> + <sec:intercept-url pattern="/FederationMetadata/**" access="isAuthenticated()"/> + <sec:intercept-url pattern="/secure/fedservlet" access="isAuthenticated()"/> + <sec:intercept-url pattern="/secure/manager/**" access="hasRole('ROLE_MANAGER')"/> + <sec:intercept-url pattern="/secure/admin/**" access="hasRole('ROLE_ADMIN')"/> + <sec:intercept-url pattern="/secure/user/**" access="hasAnyRole('ROLE_USER','ROLE_ADMIN','ROLE_MANAGER')"/> + <sec:custom-filter ref="federationFilter" after="BASIC_AUTH_FILTER" /> + <sec:custom-filter ref="logoutFilter" position="LOGOUT_FILTER"/> + <sec:custom-filter ref="federationSignOutCleanupFilter" position="PRE_AUTH_FILTER"/> + <sec:session-management session-authentication-strategy-ref="sas"/> + </sec:http> + + + <sec:authentication-manager alias="authManager"> + <sec:authentication-provider ref="federationAuthProvider" /> + </sec:authentication-manager> + + <bean id="fedizConfig" class="org.apache.cxf.fediz.spring.FederationConfigImpl" init-method="init" + p:configFile="file:./target/test-classes/fediz_config.xml" /> + + <bean id="federationEntryPoint" + class="org.apache.cxf.fediz.spring.web.FederationAuthenticationEntryPoint" + p:federationConfig-ref="fedizConfig" /> + +<!-- Works without org.springframework.security.web.authentication.session.SessionFixationProtectionStrategy as well --> +<!-- + <bean id="federationFilter" + class="org.apache.cxf.fediz.spring.web.FederationAuthenticationFilter" + p:authenticationManager-ref="authManager" p:sessionAuthenticationStrategy-ref="sas"> + + <property name="authenticationFailureHandler"> + <bean class="org.springframework.security.web.authentication.SimpleUrlAuthenticationFailureHandler" /> + </property> + </bean> + --> + + <bean id="federationFilter" + class="org.apache.cxf.fediz.spring.web.FederationAuthenticationFilter" + p:authenticationManager-ref="authManager"> + + <property name="authenticationFailureHandler"> + <bean class="org.springframework.security.web.authentication.SimpleUrlAuthenticationFailureHandler" /> + </property> + </bean> + + <bean id="federationAuthProvider" class="org.apache.cxf.fediz.spring.authentication.FederationAuthenticationProvider" + p:federationConfig-ref="fedizConfig"> + <property name="authenticationUserDetailsService"> + <bean class="org.apache.cxf.fediz.spring.authentication.GrantedAuthoritiesUserDetailsFederationService"/> + </property> + </bean> + + <bean id="sas" class="org.springframework.security.web.authentication.session.SessionFixationProtectionStrategy" /> + + <bean id="logoutFilter" class="org.apache.cxf.fediz.spring.web.FederationLogoutFilter"> + <constructor-arg name="logoutSuccessHandler" ref="federationLogoutSuccessHandler"/> + <constructor-arg name="handlers"> + <list> + <ref bean="securityContextLogoutHandler"/> + </list> + </constructor-arg> + <property name="federationConfig" ref="fedizConfig"/> + </bean> + + <bean id="federationLogoutSuccessHandler" class="org.apache.cxf.fediz.spring.web.FederationLogoutSuccessHandler"> + <property name="federationConfig" ref="fedizConfig"/> + </bean> + + <bean id="securityContextLogoutHandler" name="securityContextLogoutHandler" + class="org.springframework.security.web.authentication.logout.SecurityContextLogoutHandler"> + </bean> + + <bean id="federationSignOutCleanupFilter" class="org.apache.cxf.fediz.spring.web.FederationSignOutCleanupFilter"/> +</beans> + http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springWebapp/src/main/webapp/WEB-INF/web.xml ---------------------------------------------------------------------- diff --git a/systests/webapps/springWebapp/src/main/webapp/WEB-INF/web.xml b/systests/webapps/springWebapp/src/main/webapp/WEB-INF/web.xml new file mode 100644 index 0000000..c3b6a28 --- /dev/null +++ b/systests/webapps/springWebapp/src/main/webapp/WEB-INF/web.xml @@ -0,0 +1,64 @@ +<web-app xmlns="http://java.sun.com/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xsi:schemaLocation="http://java.sun.com/xml/ns/javaee + http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd" + version="3.0" metadata-complete="true"> + + <description> + WS Federation Spring Example + </description> + <display-name>WS Federation Spring Example</display-name> + + + + <!-- + - Location of the XML file that defines the root application context + - Applied by ContextLoaderListener. + --> + <context-param> + <param-name>contextConfigLocation</param-name> + <param-value> + /WEB-INF/applicationContext-security.xml + </param-value> + </context-param> + + <filter> + <filter-name>springSecurityFilterChain</filter-name> + <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class> + </filter> + + <!-- Optional: Cache the security token in Thread Local Storage --> + <filter> + <filter-name>FederationFilter</filter-name> + <filter-class>org.apache.cxf.fediz.core.servlet.FederationFilter</filter-class> + </filter> + + <filter-mapping> + <filter-name>springSecurityFilterChain</filter-name> + <url-pattern>/*</url-pattern> + </filter-mapping> + + <filter-mapping> + <filter-name>FederationFilter</filter-name> + <url-pattern>/secure/*</url-pattern> + </filter-mapping> + + <!-- + - Loads the root application context of this web app at startup. + - The application context is then available via + - WebApplicationContextUtils.getWebApplicationContext(servletContext). + --> + <listener> + <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class> + </listener> + + <servlet> + <servlet-name>FederationServlet</servlet-name> + <servlet-class>org.apache.cxf.fediz.example.FederationServlet</servlet-class> + </servlet> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/*</url-pattern> + </servlet-mapping> + +</web-app> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springWebapp/src/main/webapp/index.html ---------------------------------------------------------------------- diff --git a/systests/webapps/springWebapp/src/main/webapp/index.html b/systests/webapps/springWebapp/src/main/webapp/index.html new file mode 100644 index 0000000..a9dbdaa --- /dev/null +++ b/systests/webapps/springWebapp/src/main/webapp/index.html @@ -0,0 +1,25 @@ +<!-- + Licensed to the Apache Software Foundation (ASF) under one or more + contributor license agreements. See the NOTICE file distributed with + this work for additional information regarding copyright ownership. + The ASF licenses this file to You under the Apache License, Version 2.0 + (the "License"); you may not use this file except in compliance with + the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +--> +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> +<HTML><HEAD><TITLE>WS Federation Tomcat Examples</TITLE> +<META http-equiv=Content-Type content="text/html"> +</HEAD> +<BODY> +<P> +<H3>Hello World</H3> +<P></P> +</BODY></HTML> http://git-wip-us.apache.org/repos/asf/cxf-fediz/blob/31101469/systests/webapps/springWebapp/src/main/webapp/secure/test.html ---------------------------------------------------------------------- diff --git a/systests/webapps/springWebapp/src/main/webapp/secure/test.html b/systests/webapps/springWebapp/src/main/webapp/secure/test.html new file mode 100644 index 0000000..9cf7366 --- /dev/null +++ b/systests/webapps/springWebapp/src/main/webapp/secure/test.html @@ -0,0 +1,25 @@ +<!-- + Licensed to the Apache Software Foundation (ASF) under one or more + contributor license agreements. See the NOTICE file distributed with + this work for additional information regarding copyright ownership. + The ASF licenses this file to You under the Apache License, Version 2.0 + (the "License"); you may not use this file except in compliance with + the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +--> +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> +<HTML><HEAD><TITLE>WS Federation Tomcat Examples</TITLE> +<META http-equiv=Content-Type content="text/html"> +</HEAD> +<BODY> +<P> +<H3>Secure Test</H3> +<P></P> +</BODY></HTML>
