Wow! That is a hell of an answer! :-) Thanks. OK, so I understand the realms or not a good option.
I think you are right about making this a generic way to configure AMQ plugins. I will have a look at the whole resource adapters / plugins / XBean configuration stuff. About the resource-lookup and the AMQ api to use in org.apache.openejb.resource.activemq.ActiveMQ5Factory#createBroker, this is pretty much what I figured. So yes, to me this makes sense. -- Marian MULLER SERLI On Fri, May 30, 2014 at 11:54 AM, Romain Manni-Bucau <[email protected]> wrote: > Hi > > great to hear! > > About using realm I'm -1 since it has to work with openejb (without tomcat) > since that's a very current usage. > > Now how to impl it: we have to reuse AMQ logic as much as possible. You > just need to add the authenticator plugin > in org.apache.openejb.resource.activemq.ActiveMQ5Factory#createBroker. I > think this task can be more generic and should allow configuration of AMQ > plugins. > > In org.apache.openejb.resource.activemq.ActiveMQ5Factory#createBroker you > can call on the broker org.apache.activemq.broker.BrokerService#setPlugins. > So then the question is: how to get plugins? > > I'd say: either with openejb services or resources. Let suppose we use > resources (think it makes sense), I'd expect it in the conf: > > <tomee> > > <Resource id="ra" type="ActiveMQResourceAdapter"> > Plugins = plugin1, plugin2... > </Resource> > > <Resource id="plugin1" > class-name="org.apache.activemq.security.SimpleAuthenticationPlugin"> > # check XBean org.apache.xbean.propertyeditor.CollectionUtil#toMap for > the correct syntax or just use a format you think is easier > userPasswords = user1=password1\nuser2=password2 > </Resource> > > <Resource id="plugin2" > class-name="org.apache.activemq.security.SimpleAuthenticationPlugin"> > # check XBean org.apache.xbean.propertyeditor.CollectionUtil#toMap for > the correct syntax or just use a format you think is easier > userPasswords = user1=password1\nuser2=password2 > </Resource> > </tomee> > > So in summary: > > 1) add Plugins configuration to ActiveMQResourceAdapter (in class => > setPlugins(string) which will split the plugin ids and lookup them as the > datasource - see end of the mail - + attribute), in service-jar.xml > > (container/openejb-core/src/main/resources/META-INF/org.apache.openejb/service-jar.xml) > as attribute of ActiveMQResourceAdapter (think to default case where no > plugin are set we don't want to call setPlugins on the broker) > 2) check syntax we can use with > XBean org.apache.xbean.propertyeditor.PropertyEditors for plugins > > > Too lookup plugins (using resources) you need this code: > > final ContainerSystem containerSystem = > SystemInstance.get().getComponent(ContainerSystem.class); > final Context context = > containerSystem.getJNDIContext(); > final Object obj = > context.lookup(JndiConstants.OPENEJB_RESOURCE_JNDI_PREFIX + resouceId); > if (!(obj instanceof > org.apache.activemq.broker.BrokerPlugin)) { > throw new > IllegalArgumentException("Resource with id " + resouceId > + " > is not an AMQ plugin, but is " + obj.getClass().getName()); > } > > > Does it make sense? > > > > > > > Romain Manni-Bucau > Twitter: @rmannibucau > Blog: http://rmannibucau.wordpress.com/ > LinkedIn: http://fr.linkedin.com/in/rmannibucau > Github: https://github.com/rmannibucau > > > 2014-05-30 11:35 GMT+02:00 Marian Muller <[email protected]>: > > > Hi all, > > > > For starters, let me introduce myself. I am Marian Muller and I work as a > > Java EE engineer at SERLI. As part of my job, I will dedicate some time > to > > contributing to TomEE. > > > > I am working on a simpler way to configure authentication in the embedded > > ActiveMQ broker. Currently, you can easily start the embedded broker > using > > just a few lines of xml: > > > > > > > <Resource id="MyJmsResourceAdapter" type="ActiveMQResourceAdapter"> > > > BrokerXmlConfig = broker:(tcp://someHostName:61616) > > > ServerUrl = vm://localhost > > > </Resource> > > > > > > > > > But if you want to add authentication to the broker, you need to write an > > ActiveMQ xml configuration file, and - that feels a bit wrong - you need > to > > add Spring and ActiveMQ libraries in TomEE! (see > > http://tomee.apache.org/jms-resources-and-mdb-container.html) > > > > <Resource id="MyJmsResourceAdapter" type="ActiveMQResourceAdapter"> > > > BrokerXmlConfig = xbean:file:conf/activemq.xml > > > ServerUrl = tcp://someHostName:61616</Resource> > > > > > > > > > > I looked up how the ActiveMQ embedded broker is configured and started, > and > > I think it should be possible to add an option to the resource adapter to > > specify basic user/password authentication. Now I am wondering what this > > option should look like ? I see at least three possibilities: > > > > a) Specify a list of (username/password/groups) directly in the > > ResourceAdapter options (in tomee.xml). This feels a bit tedious, would > > clutter the config file and would require to define a specific syntax. > > b) Specify the path to a file (xml? properties? ...), containing the list > > of (username/password/groups). This would lighten the configuration file > > (tomee.xml) by moving away the verbose stuff. > > c) Maybe we could reuse the existing user database from > > conf/tomcat-users.xml ? This way we only need a single file to configure > > all the users. > > > > > > This is for the simple username/password authentication, which would use > > ActiveMQ's SimpleAuthenticationPlugin. > > > > Now maybe a better way to add JMS authentication would be to reuse the > > existing Realm, which can be configured by the users. This would probably > > require to write a custom ActiveMQ plugin that checks authentication > > against the realm. But this would open much more authentication options! > > Now, if you don't mind, I could use some pointers on how to reuse this > > Realm, and also how to define another realm for JMS authentication (if > the > > user wants so)? > > To me, this feels like a better way to centralize authentication in > Tomcat > > Realms! > > > > What do you think? How do you see JMS authentication? > > Please tell me if I am going the wrong way here. > > I could definitely use the community feedback here! :) > > > > Thank you. > > -- > > Marian MULLER > > SERLI > > >
