users@glassfish.java.net

Re: Trouble with authorization with my EJB.

From: <glassfish_at_javadesktop.org>
Date: Tue, 22 May 2007 16:56:39 PDT

Ron,

First off, thank you [b]very[/b] much for taking the time to reply to my questions. Thank you [b]all[/b] for your continued patience and effort in helping me with this problem.

It had not occurred to me that @RolesAllowed would be implemented using a policy file type setup, that's interesting and makes a lot of sense now.

Here's my granted.policy file:
[url=http://jeffrey.rodriguez.googlepages.com/granted.policy.txt]granted.policy[/url]

I set my security logging to finest and had the output linked below.

[url=http://jeffrey.rodriguez.googlepages.com/test1.txt]test1[/url]
Intended role mappings:
application_assets_read
application_assets_write

[url=http://jeffrey.rodriguez.googlepages.com/jrod.txt]jrod[/url]
Intended role mappings:
application_assets_admin
application_assets_read
application_assets_write

Two other things that might be helpful: I'm using the LDAP backend. I do not have any xml ejb deployment descriptor.

If there's anything else I can provide, let me know
[Message sent by forum member 'jeffreyrodriguez' (jeffreyrodriguez)]

http://forums.java.net/jive/thread.jspa?messageID=218445