01: /*
02: * JBoss, Home of Professional Open Source
03: * Copyright 2007, JBoss Inc., and individual contributors as indicated
04: * by the @authors tag. See the copyright.txt in the distribution for a
05: * full listing of individual contributors.
06: *
07: * This is free software; you can redistribute it and/or modify it
08: * under the terms of the GNU Lesser General Public License as
09: * published by the Free Software Foundation; either version 2.1 of
10: * the License, or (at your option) any later version.
11: *
12: * This software is distributed in the hope that it will be useful,
13: * but WITHOUT ANY WARRANTY; without even the implied warranty of
14: * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15: * Lesser General Public License for more details.
16: *
17: * You should have received a copy of the GNU Lesser General Public
18: * License along with this software; if not, write to the Free
19: * Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
20: * 02110-1301 USA, or see the FSF site: http://www.fsf.org.
21: */
22: package org.jboss.test.web.servlets;
23:
24: import java.io.IOException;
25:
26: import javax.servlet.ServletException;
27: import javax.servlet.http.HttpServlet;
28: import javax.servlet.http.HttpServletRequest;
29: import javax.servlet.http.HttpServletResponse;
30:
31: import org.jboss.web.tomcat.security.login.WebAuthentication;
32:
33: //$Id$
34:
35: /**
36: * JBAS-4077: Programmatic Web Login
37: * Servlet picks up the username, password from the request parameters
38: * and then does the web authentication
39: * @author Anil.Saldhana@redhat.com
40: * @since Mar 12, 2007
41: * @version $Revision$
42: */
43: public class ProgrammaticLoginTestServlet extends HttpServlet {
44: private static final long serialVersionUID = 1L;
45:
46: protected void service(HttpServletRequest request,
47: HttpServletResponse response) throws ServletException,
48: IOException {
49: String username = request.getParameter("username");
50: String pass = request.getParameter("pass");
51:
52: if (username == null || pass == null)
53: throw new RuntimeException("username or password is null");
54: WebAuthentication pwl = new WebAuthentication();
55: pwl.login(username, pass);
56:
57: //Only when there is web login, does the principal be visible
58: log("User Principal=" + request.getUserPrincipal());
59: log("isUserInRole(Authorized User)="
60: + request.isUserInRole("AuthorizedUser"));
61: if (request.getUserPrincipal() == null
62: || !request.isUserInRole("AuthorizedUser"))
63: throw new ServletException(
64: "User is not authenticated or the isUserInRole check failed");
65:
66: //Log the user out
67: pwl.logout();
68:
69: if (request.getUserPrincipal() != null
70: || request.isUserInRole("AuthorizedUser"))
71: throw new ServletException(
72: "User is still authenticated or pass: isUserInRole(Authorized User)");
73: }
74: }
|