Peter, I'd recommend you check out OSUser at www.opensymphony.com. It is very good for doing custom user management for not only orion, but other app servers.
-Pat ----- Original Message ----- From: "Peter van Rensburg" <[EMAIL PROTECTED]> To: "Orion-Interest" <[EMAIL PROTECTED]> Sent: Tuesday, April 02, 2002 7:34 PM Subject: Re: HttpServletRequest.isUserInRole() and Orion > Oops :) Missed the inner class inside SimpleUserManager, ignore comments > about missing methods in Orion interfaces, doh! :) > > On Tue, 2002-04-02 at 14:30, Peter van Rensburg wrote: > > Hi > > > > I'm putting together a customer user manager for orion, extending > > com.evermind.security.AbstractUserManager, with UserWrapper and > > GroupWrapper classes implementing com.evermind.security.User and > > com.evermind.security.Group respectively. > > > > Now HttpServletRequest.isUserInRole() used to call User.isMemberOf() > > back in the days of <= 1.4.0, this however does not seem to be the case > > anymore. isMemberOf() still gets called to satisfy the > > <security-constraint>s in web.xml. > > > > Looking at the example on orionsupport.com, three abstract methods are > > mentioned: > > > > protected boolean userExists( String username ); > > protected boolean checkPassword( String username, String password ); > > protected boolean inGroup( String username, String groupname ); > > > > It doesn't appear that HttpServletRequest.isUserInRole() gets trunked > > through to inGroup() nor do I see these three methods in any Orion > > interface definition ? > > > > Does anyone know how to fix this? Or how > > HttpServletRequest.isUserInRole() gets handled by Orion ? > > I've search the mailing list archive and it seems that other users have > > also encountered these problems but it never got sorted out ? > > > > Many thanks for any assistance, > > Peter > > > > > > > > > > > >
