Authorization and authentication ADF

Hello world

I have a request for the adf, including the following files:

MyLogin.html that is my login page (post to j_security_check) and two jsf pages.

/Secure1/Secure1.JSPX
/ secure2/secure2. JSPX

I have configured the adf security and created two users, user1 and user2, application roles two, aRole1 and aRole2 and two roles of enterprice, eRole1 and eRole2.

I configured policies the adf for two pages, which gives a read access to /secure1/Secure1.jspx to aRole1 and /secure2/Secure2.jspx to aRole2.

When I run the application and try to access Secure1.jspx, I get redirected to the login page. When I try the User1 credentials, am poster page, and that's fine.

However, if I try to access the page Secure1.jspx with the credentials of user 2, I get error 401. Also when I try to provide the weblogic user credentials, yet once I get 401.

How can I capture and customize the 401 error?

Thank you
Antonis

Antonis,

Have you tried to put code like this in your web.xml file?


401
/error.jsp

John

Tags: Java

Similar Questions

  • Authorization and authentication external Weblogic Portal

    In our project we use Weblogic portal 10.3 and Oracle 11 g as a backend. During the creation of the field, I specified Oracle as backend. All schemas relevant portals are created in the Oracle database. For our application, we created a specific schema. In a specific scheme of project, we have the table user containing fields like username, password, e-mail, and other relevant areas. How to configure in weblogic to access this table for authentication instead of the user portal schema table? As well as I need to know, in a console of Directors if a new user is created, and then details will be stored in a table schema portal or a project schema user table? In the end, I want to configure specific project table to store the information of the user when the user created through the administrative console.

    It's urgent.

    Hi Renon
    Basically, you need to authenticator custom to store and authenticate all your users to your own specific Tables DB (with information from the user). For this you need to develop custom authenticator. Please note that this has nothing to do with the portal. It's core weblogic security stuff. I have compiled a few links for you. Incase if Oracle Support, open a ticket with them have Oracle support work entirely custom authenticator sample of RDBMS that stores and authenticates users of specific set of custom tables. They will send you immediately. I hope that someone in these forums can have this example also in their personal blogs/forums.

    And, Yes, you can force your custom authenticator to be one by default and to store users when you create new users in the administration Console. Essentially, when you create new users, you should see the option as to create users in what way authentication provider.

    http://download.Oracle.com/docs/CD/E12840_01/WLS/docs103/dvspisec/ATN.html (authentication providers)

    http://download.Oracle.com/docs/CD/E12840_01/WLS/docs103/dvspisec/ATN.html#wp1145342 (do you need to develop a custom authentication provider?)

    http://download.Oracle.com/docs/CD/E12840_01/WLS/docs103/dvspisec/ATN.html#wp1089150 (how to develop a custom authentication provider)

    http://download.Oracle.com/docs/CD/E12840_01/WLS/docs103/secmanage/ATN.html#wp1204261 (by changing the order of authentication providers)

    Thank you
    Ravi Jegga

  • Authorization and authentication in FLEX

    To what extent is it possible to feed my webservice call with a user name and password for the back-end system?

    I tried the bot the SetCredentials and SetRemoteCredentials on my webservice object, but somehow flex ignores.

    Any idea?

    Hello
    I don't know if this can help, in your case, but in my webservice is used ws security username and password Im sending in header:

    var qname:QName = new QName (wsseNamespace, 'Security');
    var header: SOAPHeader = new SOAPHeader (qname, {object with username and password});
    myWebService.addHeader (header);

    LK

  • ACS - ASA authorization and accounting

    Hello

    I have a few questions about the authorization and accounting on the ASA via an ACS server

    1. When I activate the command 'aaa authorization command' users of SSH commands I get locked on console then I have to configure the console, telnet and allow to be authenticated via Ganymede too, is it possible to allow SSH via Ganymede while keeping the Console and telnet authenticated locally or not even no authentication?
    2. I visited command 'aaa accounting TAC' accountant on ASA, but I noticed that GBA records just mod configuration commands ' focus on in 15 "not show all command or privilege 1, is possible to fix this?"»
    3. RADIUS supports authorized SHELL?

    Thank you for your support

    1.] Unfortunately, it is currently not possible to exclude the command authorization serial number / console or ssh to users while having it apply to other methods of access in the case of ASA. Once you run this command, it would be applicable to all methods such as ssh, telnet, http, enable and console. This can be easily achieved by IOS (routers and switches) by creating a list of method.

    2.] when configuring the aaa accounting command , each other than display command command commands entered by an administrator is recorded and sent to accounts or servers. This is a default behavior on the SAA. IOS send/check orders show on ACS/Ganymede.

    http://www.Cisco.com/en/us/docs/security/ASA/asa81/command/ref/A1.html

    Kind regards

    Jousset

    The rate of useful messages-

  • Authorization without authentication

    Hello

    From Java code, is it possible to query Weblogic LDAP users/groups without requiring a password?  I use an application Java with Weblogic 12.1.2 configured to point to an external LDAP server.  From a java client, I would use the Windows user name, and the query LDAP to view the groups to which the user is in.  It seems that this is possible by using SessionContext.getCallerPrincipal () but I always get 'Anonymous', I think just because the user has not been authenticated.  Is there a way to get information from a user/group LDAP using the Weblogic Server Java without an authenticated user?

    Thanks for any information!

    It is not possible to make an authorization without authentication of the user first.

    In the case of Kerberos, it uses authentication that is already at the computer level (when you connect to the system).

    So I think that Kerberos is the only option.

  • When Windows starts, it starts also Mozilla and an adf.ly page appears.

    I myself Adf.ly Skipper, but firefox always starts with windows and ot adf.ly it load Google.com. All - tried reset firefox, anti-virus, backup even my computer. I'm never mozilla start with windows or install adf.ly or anything... What can I do else? Help!

    If you change your browser by default for Internet Explorer, the page opens in Internet Explorer the next time? This would be the common model for external pages, they are targeted on the default browser.

    Microsoft has a utility named autoruns, you can use to see what is configured to run at startup (opening session): https://technet.microsoft.com/en-us/s.../bb963902.aspx. I hope that this will help in tracking it.

  • Message violates guidelines send IPv6 on PTR 550 5.7.1 documents and authentication

    I use OS X Server (El Capitan) as my personal mail server. Everything is set up correctly. Mail works fine for everything except google gmail. This has happened for 2-3 years... whenever I have send emails to users of Gmail, I get "reviewed mail returned to sender" which explains "this message does not respect guidelines send IPv6 on PTR 550 5.7.1 records and authentication»

    How can this be repaired?

    I resolved to myself.

    After digging the question (there is a post in the communities of Apple Support by Paul Derby 'Blocks Google's IPv6 email receipt sent by OS X Server'), I found the hack to force postfix to use IPv4 only not for work.

    Instead of this, I found myself setting the configure IPv6 in the 'link-local only' in the advanced configuration of network Ethernet. (She had been established to 'Automatically', perhaps by default, when update OS X - Server some time ago.)

    I can now send to addresses gmail from my client devices without problem. However, it seems that the accessibility of the Internet is not working now and so I disabled it (a small price to pay).

  • appleTV ask code appleID password and authentication circularly

    After the update to my iPhone I have asked me to use the double authentication code, I didn't have any idea what kind of nightmare is. I spent hours to go from one device to the other verification of passwords and authentication codes. The last of them is the Apple TV after this stupid innovation my appleTV ask my code AppleID password and authentication, then goes back to the request of the appleID. Basically, my AppleTV is useless. How can I eliminate the stupid passcode, which makes all my devices basically inaccessible?

    Turn off step 2 or two factors:

    For Apple ID - Apple Support two-factor authentication

    Frequently asked questions about the audit in two steps for Apple ID - Apple Support

    Others have reported problems with them when it is used with the Apple TV.

  • My outlook express won't let emails through. I am getting an authorization and then an error will appear.

    Outlook express won't come through

    My outlook express won't let emails through. I am getting an authorization and then an error will appear. Sometimes it will say: reception of messages, but none will come by.  A box appears and says that he put an end to the connection, maybe because of the connection to the server, the long period of inactivity or network connection. Also, I get a message on and which was completely removed several times on the file inbox and delete. I have no idea how to solve this problem or what I did to make it. I've never experienced this before.

    You probably have the widespread corruption of dbx files. Try in a new identity.

    File | Identities | Add the new identity. Create a new one and try it. If all goes well, you can import your messages and address book from the old identity and delete it.

    Note: Do not use the main word in the name of the new identity.

    In addition, follow these guidelines to help avoid this in the future.

    Do not archive mail in the receipt or sent items box. Create your own user-defined folders and move messages you want to put in them. Empty the deleted items folder daily. Although the dbx files have a theoretical capacity of 2 GB, I recommend all a 300 MB max for less risk of corruption.

    Information on the maximum size of the .dbx files that are used by Outlook Express:
    http://support.Microsoft.com/?kbid=903095

    After you're done, followed by compacting your folders manually while working * off * and do it often.

    Click Outlook Express at the top of the the folder tree so no folders are open. Then: File | Work offline (or double-click on work online in the status bar). File | Folder | Compact all folders. Don't touch anything until the compacting is completed.

    Disable analysis in your e-mail anti-virus program. It is a redundant layer of protection that devours the processors and causes a multitude of problems such as time-outs and account setting changes. Your up-to-date A / V program will continue to protect you sufficiently. For more information, see:
    http://www.oehelp.com/OETips.aspx#3

    And backup often.

    Outlook Express Quick Backup (OEQB Freeware)
    http://www.oehelp.com/OEBackup/default.aspx

  • I'm trying to install Office note 8.1 but get this error message immediately after you enter the serial number and authentication code.

    Remark Office OMR

    I've been remark office omr 8.1 installed on 32-bit windows vista (intel pentium DC) for the last year laptop. Now plan to move it to a more recent hardware and the OS.

    I'm trying to install Office note 8.1 on Windows 7 Home Basic 64 bit (on laptop AMD E450 DC base). But am getting this error message immediately after you enter the serial number and authentication code. I tried to install different versions of the .net Framework (from 1.1 to 4), but nothing seems to solve the problem.

    I even tried to install it in mode compatibality. but no luck.

    Here is the error message (between BEGIN and END lines)

    -BEGIN-

    An error occurred instantiating the object of authentication. Please restart your computer, and they run the Setup again.
    Error number = 2147219705

    Error = description

    ------ END--------

    Appreciate any help

    Thank you

    SJ

    Just for the follow-up of this: I have sent comments, and they responded in 20 minutes with:

    Please contact the Support of the note.  I'm sorry that you are experiencing this error, but it seems by the error message that you install note on a Windows 7 computer.  This error is caused by a Microsoft security update that was released in July 2011 for Windows 7 and caused upward to change our software.  Here is access to our Download Center for you to install the version 8.4 of note.  You will use your current serial number, license key and authentication code.
    They then provided a link to their Download Center where I could download 8.4
    E - mailer to * address email is removed from the privacy * and they will answer you. They have great customer service.
  • You can change the manual HTTP Proxy on windows 8 / Surface Access Sever, Port, and authentication

    On the iPhone and iPad, you can go on the Wi - Fi connection settings tap modern you have.  After that, you change the HTTP Proxy in manual.  Once you press it, you can put server, port, and authentication that put my school.  You can access these things on Windows 8 or the Surface Pro?

    I need to connect to the school for Wi - Fi to access the internet.

    Hello

    To change the proxy settings, try the following steps.

    (a) press the Windows key + R, type inetcpl.cpl , and then press enter.

    (b) click on the connections tab, and then click LAN settings.

    (c) put check Mark to use a proxy server for your LAN check box.

    (d), and then make your changes in the settings. You can also click on the Advanced tab for more options.

    (e) after making necessary changes click on apply then Ok to save the changes.

    Check out the link for more information.

    To connect to the Internet
    http://Windows.Microsoft.com/en-in/Windows-8/connect-Internet

    Hope this information helps. Answer the post with an up-to-date issue report to help you further.

  • Doesn't have JHeadstart capable of converting Forms 10g times 11g and 10g ADF Faces?

    We would like to buy for JDeveloper 10.1.3.3 JHeadstart generator g 10 forms to ADF Faces. This version of JHeadstart capable of converting forms 10g 10 g ADF Faces. But I want a universal JHeadstart generator ADF Faces, who will be able to convert forms 10g times 11g and 10g ADF Faces. Please help me by your valuable suggestion/advice.

    Try asking on the JHeadstart forum:
    JHeadstart

    As far as I KNOW, JHeadstart 11 g is still not released.

  • is it possible to use two external LDAP and authentication of external Table?

    Hi, is it possible to use both external LDAP and authentication of the external table?

    they all need two initialization blocks to access a session system variable, USER?

    Thank you

    Hello
    I don't think it's possible to impliment the LDAP authentication both extenal together. The reasons are,
    1. we cannot define two sources (LDAP and Extenal DB) in the same blocks of justine initialization user information.
    2. If two different (one for LDAP) initialization blocks and one for extenal DB are used, we cannot use variable USER twice it's a defined system variable.

    Thank you
    Swami

  • ADF security and authentication of the forms

    I created a form simple adf using the Department in the form of the adf. Run - work

    I then put the adf security implemented, create login.htm error.html and /faces/mydept.jspx

    When I right click on the login.html and run, I get the access code, I signed with the user and get 403.
    When I right click on the mypage.jspx and run, I get the connection, I login with the user and work?

    so my question for which url do I give to the user once I have move to production
    (1) http://...:7xxx/context/login.html
    or (2) http://...:7xxx/context/faces/mypage2.jsp



    TKS

    You can send a http://...:7xxx/context/faces/mypage2.jspx

    ADF is a technology jsf the web.xml file will be a filter for faces and is the filter of the address provided and it is treated.

    THS peace of code in the web.xml file is responsible for the filter and treatment

    > Faces Servlet
    > /visages / *

  • I get error when I do authention adf using SQLAuthenticator

    Hi Experts ADF,

    JDeveloper 11.1.1.7.0

    I follow the blog below to create a SQLAuthenticator and the data source

    Java / Oracle SOA blog: the use of tables of database as in WebLogic authentication provider

    Finally, I am able to see the users and groups in the WLS Console.

    I see users like AHUNOLD and SKING and both are mapped to USER groups and ADMIN.

    Now in my application if I do a default authentication and authorization. And on successful redirection I point to the welcome.jspx page.

    Jazn-data, I created 2 roles of the company with the same name as a USER and ADMIN. And 2 application role created USER_APP and ADMIN_APP.

    And business roles are mapped to Application roles. Grants resources home page is given to USER_APP and ADMIN_APP.

    Now if I run the page, automatically the data are removed from JHS_ROLES automatically.

    And the below error I get log

    [08: 08:17] roles jazn-data download.

    [08: 08:17] remove the group existing 'ADMIN '.

    [08: 08:17] Creation of group for role "ADMIN".

    [08: 08:18] ERROR: could not create the group "ADMIN".  Reason: weblogic.security.providers.authentication.DBMSSQLAuthenticatorDelegateException: [Security: 090269] error adding the ADMIN group

    [08: 08:18] remove the group existing 'USER '.

    [08: 08:18] Creation of group for role "USER".

    [08: 08:18] ERROR: could not create the group "USER".  Reason: weblogic.security.providers.authentication.DBMSSQLAuthenticatorDelegateException: [Security: 090759] A SQLException occurred when retrieving USER information

    Do I need to make any changes in the weblogic.xml file or anywhere?

    Currently my weblogic.xml file looks like to below: -.

    <? XML version = "1.0" encoding = "windows-1252"? >

    " < weblogic-web-app xmlns: xsi =" http://www.w3.org/2001/XMLSchema-instance "

    " xsi: schemaLocation =" http://www.BEA.com/ns/WebLogic/WebLogic-Web-app http://www.bea.com/ns/weblogic/weblogic-web-app/1.0/weblogic-web-app.xsd"" "" "

                      xmlns=" http://www.BEA.com/ns/WebLogic/WebLogic-Web-app ">

    < security-role-assignment >

    valid users - < role name > < / role name >

    users of < SPN > < / main-name >

    < / security role assignment >

    < / weblogic-web-app >

    Thank you

    Roy

    Thanks for the reply... I solved the problem... it was under properties of the Application--> Deployment---> uncheck users and groups.

Maybe you are looking for

  • Subscribed calendar works on Mac, but not iPhone

    I have a calendar on my Mac (http://docs.smsd.org/districtCalendar/ics/?id=1009http://docs.smsd.org/districtCalendar/ics/?id=1009) and you can see the events, but on my iPhone, I can see the calendar, but there is no events. I tried to subscribe to t

  • Satellite L50 - A - 16 G - how to upgrade RAM?

    I have a Satellite L50 a 16G with 4 GB of RAM and I would like to move to 8 GB, but I don't know what memories are compatible with my PC.I tried to present that the serial number on the Support from Toshiba page but tells me that is not valid, as the

  • W500 has not detected a good size of HARD drive

    I am trying to picture a W500 using MDT 2010 Update 1. I have a 80 GB HARD drive installed (tried several different readers) MDT is set to partition the HARD drive to 100% The problem is that when it breaks and format the HARD drive, it does just 1 G

  • 003-centon MP3 2GB USB Media Player

    Layer of media don't recognize this drive and allow me to sync the device, so I can't add mp3 files

  • I have a problem with my e mail

    I have a problem with my e mail