webtier@glassfish.java.net

Re: Web applications access control

From: Bernhard Thalmayr <bernhard.thalmayr_at_painstakingminds.com>
Date: Thu, 15 Dec 2011 15:42:30 +0100

by 'accessible internally' ... do you mean it should not be available
'externally' at all or only accessible with proper authorization?

If you mean the first one I don't think this is possible as you can only
'assign' the whole application to a virtual server, not parts of it.

If you can separate the two web-apps into two apps then you can use
virtual server concept. However if one knows what to do it can easily be
bypassed ... so it's not really secure.

Another possibility would be to frontend GF with a 'reverse-proxy' kind
of thing which does not allow to request specific URIs.

-Bernhard



On 12/15/2011 03:09 PM, forums_at_java.net wrote:
>
>
> Hi All,
>
> i am using glassfishv2.x for my project. we have a EAR file in
> that two web application are there. my client requirment is one web
> application should accessab all [public] and another one should not be
> accessable to public that shoud be accessable to local ips [internal] . i
> really dont know how to configure the server for the same requirement. i
> tried it in the net , some are suggesting that we can achieve the same with
> virtual server concept but i did not get . please help me.
>
> Regards
>
> Guru...
>
>
>
>
> --
>
> [Message sent by forum member 'guruvulubojja']
>
> View Post: http://forums.java.net/node/874293
>
>
>


-- 
Painstaking Minds
IT-Consulting Bernhard Thalmayr
Herxheimer Str. 5, 83620 Vagen (Munich area), Germany
Tel: +49 (0)8062 7769174
Mobile: +49 (0)176 55060699
bernhard.thalmayr_at_painstakingminds.com - Solution Architect
This e-mail may contain confidential and/or privileged information.If 
you are not the intended recipient (or have received this email in 
error) please notify the sender immediately and delete this e-mail. Any 
unauthorized copying, disclosure or distribution of the material in this 
e-mail is strictly forbidden.