All Downloads are FREE. Search and download functionalities are using the official Maven repository.

org.apache.ctakes.ytex.web.beans-security.xml Maven / Gradle / Ivy

The newest version!
<?xml version="1.0" encoding="UTF-8"?>
<!--

    Licensed to the Apache Software Foundation (ASF) under one
    or more contributor license agreements.  See the NOTICE file
    distributed with this work for additional information
    regarding copyright ownership.  The ASF licenses this file
    to you under the Apache License, Version 2.0 (the
    "License"); you may not use this file except in compliance
    with the License.  You may obtain a copy of the License at

      http://www.apache.org/licenses/LICENSE-2.0

    Unless required by applicable law or agreed to in writing,
    software distributed under the License is distributed on an
    "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
    KIND, either express or implied.  See the License for the
    specific language governing permissions and limitations
    under the License.

-->

	<!--
  - Sample namespace-based configuration
  -
  -->

<beans:beans xmlns="http://www.springframework.org/schema/security"
	xmlns:beans="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
	xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
                        http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security-3.0.xsd">

	<global-method-security pre-post-annotations="enabled">
		<!--
			AspectJ pointcut expression that locates our "post" method and
			applies security that way <protect-pointcut expression="execution(*
			bigbank.*Service.post*(..))" access="ROLE_TELLER"/>
		-->
	</global-method-security>

	<http use-expressions="true">
		<intercept-url pattern="/**" access="hasRole('ROLE_USER')" />
		<!--
			Disable web URI authorization, as we're using
			<global-method-security> and have @Secured the services layer instead
			<intercept-url pattern="/listAccounts.html" access="isRememberMe()"
			/> <intercept-url pattern="/post.html"
			access="hasRole('ROLE_TELLER')" />
		-->
		<form-login />
		<logout />
		<remember-me />
		<!--
			Uncomment to enable X509 client authentication support <x509 />
		-->
		<!-- Uncomment to limit the number of sessions a user can have -->
			<!--
		<session-management invalid-session-url="/timeout.jsp">
				<concurrency-control max-sessions="1"
				error-if-maximum-exceeded="true" />

		</session-management>
			-->

	</http>

	<!--
		Usernames/Passwords are rod/koala dianne/emu scott/wombat peter/opal
	-->
	<authentication-manager>
		<authentication-provider>
			<password-encoder hash="md5" />
			<user-service>
				<user name="rod" password="a564de63c2d0da68cf47586ee05984d7"
					authorities="ROLE_SUPERVISOR, ROLE_USER, ROLE_TELLER" />
				<user name="dianne" password="65d15fe9156f9c4bbffd98085992a44e"
					authorities="ROLE_USER,ROLE_TELLER" />
				<user name="scott" password="2b58af6dddbd072ed27ffc86725d7d3a"
					authorities="ROLE_USER" />
				<user name="peter" password="22b5c9accc6e1ba628cedc63a72d57f8"
					authorities="ROLE_USER" />
			</user-service>
		</authentication-provider>
	</authentication-manager>

</beans:beans>




© 2015 - 2025 Weber Informatics LLC | Privacy Policy