Figured it out:  jboss-web.xml was not in the right place


-----Original Message-----
From: Emily Short
Sent: Wednesday, October 09, 2002 1:36 PM
Subject: RE: [JBoss-user] security_check


More info about this problem:

I am using JBoss 3.0.3/Jetty and can’t see java:/jaas/testAppSecurity in my JNDIView.  I must be missing an obvious step somewhere.




-----Original Message-----
From: Emily Short
Sent: Wednesday, October 09, 2002 12:20 PM
Subject: [JBoss-user] security_check


I am trying to get j_security_check working but for some reason I am allowed to login no matter what bogus username and password I enter (or if I enter none at all).  I want to use the DefaultDB (Hypersonic) in order to authenticate, but I haven’t modified the DB at all yet so it seems to me that any attempt to login should fail.  I do not see any activity on the server when I log in.  Your help is appreciated




<application-policy name="testAppSecurity">


          <login-module code = "" flag="required" >

             <module-option name="dsJndiName">java:/DefaultDS</module-option>

             <module-option name="principalsQuery">SELECT passwd FROM Users WHERE username=?</module-option>

             <module-option name="rolesQuery">SELECT user_roles from UserRoles where username=?</module-option>











         <web-resource-name>Secure Content</web-resource-name>

         <description>An example security config that only allows users with the role AuthorizedUser to access restricted content</description>


















      <description>Role required to access restricted content</description>














login.jsp snippet:


<form method="post" action="j_security_check">

Username: <input type="text" size="20" name="j_username">


Password: <input type="password" size="20" name="j_password">


<input type="submit" value="Login">



Reply via email to