Security of the URL scheme

I use JDev 11.1.2.3 and trying to protect the resources for a certain model of URL in my ADF application.  I tried to change my web.xml file to add the security constraint, but seems to have no effect.  I added the following entry to my web.xml:

< security constraint >

< web-resource-collection >

resources of < web-resource-name > < / web-resource-name >

< url-pattern > /afr / * < / url-pattern >

< / web-resource-collection >

<>auth-constraint

valid users - < role name > < / role name >

< / auth-constraint >

< / security constraint >

What I want to achieve, is to have all of the resources, with the pattern URL/afr / *, accessible only if authenticated.  For example, I don't want someone capable of displaying a js to afr/partition/ie/default/opt/core-SHERMAN-1147.js file. Please let me know if I go about it the wrong way or if there is a better way to do it.  Thank you for any input you can provide.

Thank you

Jessica

It works correctly if you put the resource under the filter adfAuthentication filter in the web.xml file? (Which you're not supposed to do though).

Ideally, your unsecured pages also will need these resources (FWIW, afr is the resource filter, serving resources - like image, js etc files to the application). So, you don't have to be fi establishing. That would mean that your pages not secure / public pages could not be restored correctly.

Arun-

Tags: Java

Similar Questions

  • Where can I get the URL scheme for adding / deleting/search a contact of the people app

    Original title: application Windows 8 Metro people...

    Where can I get the URL scheme for adding / deleting/search a contact of the people app

    It is not a URI API for this application.

  • Is it possible to open a folio to a specific page of external links using the URL scheme?

    We want to link in a folio of another application we create.   We can open the application Viewer with the URL scheme that we define in the application (for example, com.name.app).   However, it always opens the application on the home screen.

    Ideally, we would like to link in a specific portfolio or a single page in the folio.  Is this possible using a sort of chain of request/identifier/anchor on the end of the URL scheme?

    Yes, its possible, but officially not supported and is not fully tested. Check the DPS tips App by Bob Bringhurst (https://itunes.apple.com/in/app/digital-publishing-suite-tips/id436199090?mt=8)

    Download Advanced Overlay folio and check "Buttons & Linking" - slide 2

  • url schema custom onto the pages of simple editing

    Hi, I have a question about custom url scheme on simple edition folios... it seems that this feature is only available on edition folio multi... If Yes... Why?, I mean, why is not possible for simple editing users access this feature... the ability to communicate the child with the parent... Web content overlay with folio to navigate within a folio... ?

    Thanks in advance

    It seems that this is what is happening. If you are a user of unique serial number edition show us the custom field of the url scheme. If you go through the creative workflow cloud we don't have. My guess is that it was a decision of design made to simplify the workflow creative Cloud for most customers, since "custom url scheme" is a bit complicated and not many people simple edition have a use for it.

    Neil

  • Security of the ADF

    Hi all

    We have a SignIn page in our application for the authentication of the user and all components. In the ADF - config.xml, I have the following Setup

    authorizationEnforce = "false" authenticationRequire = "true".

    but I was redirected to the main home page (the page will be sent after a successful authentication) without any authentication. Although I put authenticationRequire = 'true '.

    However, if I set the URL scheme as ' / ' in the security constraint. It opens the SignIn page. However, the images were not properly?

    When the ADF security is enabled, i.e. when the two indicators of authentication/authorization in afc - config.xml are enabled, it works correctly.

    Please help us.

    Hello

    However, if I set the URL scheme as ' / ' in the security constraint. It opens the SignIn page.

    That's what the assistants of ADF Security adds by default when you select authentication only because there is no authorization, leading to a delayed authentication

    However, the images were not properly?

    This is because "/" protects all files under the root of Java EE. To change this, change the constraint "/" for authentication *.jspx (or *.jsp If you are using this as a file extension). In this case the images are excluded from security

    (Note that it is not here ADF security, but the security of web applications in Java EE)

    When the ADF security is enabled, i.e. when the two indicators of authentication/authorization in afc - config.xml are enabled, it works correctly.

    This is because the permission is not applied on the level of path (your path of the application root) context Java EE

    Frank

  • Can we deep link from another application to a single app with url schema question?

    Hello

    Is it possible to deep link to another application or browser to an exemplary application installed on the iPad via the URL schema?

    We have a customer who want to link their own app (nonDPS) an application to the only question that we have built for him.

    We have an Adobe Enterprise license.

    Cheers, Tony

    I thought about it - it's: custom-url: / / (for example com.publisher.magazine://) and it works

    Cheers, Tony

  • Opening a Single-App URL scheme

    Hello

    I created a Single-App (Folio: 2048 x 1536) with the URL scheme.

    I installed and that you call from Safari.

    but it crashed after it displays a splattered image.

    The Single-App works well on the new iPad.

    Any answer or advise is appreciated.

    shimoawazu

    Although these articles are on Wallaby, they offer different techniques to avoid looping of the animation:

    http://InDesignSecrets.com/from-InDesign-to-HTML5-via-Flash.php

    http://digitalpublishing.Tumblr.com/post/3898796141/animate-headlines-or-other-things

  • Everytime I open a new website, firefox deletes the url and it goes to research, I fear that this could be a security bug, help?

    Any Web site, that is, it started yesterday, I will click on a link or something in that sense. For example, Google. I go to google.comand start typing, rather than appear in the search bar, it appears in the URL bar. He also does this on any website that I sign, another example being the site of my college, in which I am really hoping that this is not a security bug because it would mean very bad news!

    It seems that the resettlement of firefox was the key to fix. But I had to lose all my favorites in the process. =(

  • How can I change the URL in a bookmark? For security reasons, the site instantly takes me to the login page, but remember the URL, I entered and need me the tray

    I want to change the text of the URL in a bookmark. When I manually enter the URL in the address bar of Firefox, the site takes me immediately to the secure login page, but he remembers the URL at which I entered. I can't 'bookmark this page' because then I get only the page of connection, and the future visits the site will have no idea of that, different URLS, I wonder. So, I want to create individual bookmarks for each of my used URLs, even if they all route me via the same secure login page.

    Hello Pierre, you can change the url of a bookmark in the library of bookmark which you can access through the menu bar > bookmarks > show all bookmarks -simply select the bookmark you want to edit, then you can edit its properties at the bottom of the window.

  • Why can't I see a padlock in the URL bar Bank / purchase etc. with Firefox? How can I find out link is secure?

    Usually, when banking, or buy something online, there will be
    a padlock symbol to ensure that your transaction/payment information is secure. This is usually seen in the address URL search bar, but I don't see that with Firefox. Why?

    You have more the Status bar which showed the padlock in previous versions of Firefox in Firefox 4.

    The padlock shows only that there is a secure connection and does not guarantee that you are connected to the right server.

    So you could always be connected to the wrong server if you make a typing mistake in the URL and someone said that mistyped the URL.

    The lock feature has been replaced by the How do I know if my connection to a Web site is secure? on the left end of the address bar.

    See also:

    You can use this extension to get a lock on the address bar.

  • Save the custom URL scheme

    Hello!

    Is it possible to save a custom url scheme so that the system will launch my application when the user clicks on a link in the form "customscheme://idontcareaboutthefqdn/"?

    I know you can record a complete domain name by using HttpFilterRegistry, but I really want to react to a plan.

    P.S.: As always, I forgot to include the most important information...
    BB 6.0.0 API

    THX

    A few quick answers:

    (1) ignore, memory shows just a nodule not RIM started

    (2) interesting

    (3) care

    Now, I have a theory here.  I think you are trying to add the template registry etc until your application has actually started.

    If you look at this statement:

    PatternRepository.addPattern (ApplicationDescriptor.currentApplicationDescriptor (), "^ regime:-/-/ \\S*",)

    This is handled in your main() and main is no NOT part of your application - it is used to start your application.  (in fact it becomes part of your Application, but it's out of reach for the moment). So what makes ApplicationDescriptor.currentApplicationDescriptor () actually refers to?  A null descriptor, perhaps?

    I would try to reworjk that so as the record of the model becomes an integral part of your Application, so that ApplicationDescriptor.currentApplicationDescriptor (done) actually refers to the application you want.  Something along these lines - do 'with it ':

        public static void main(String[] args) {
            MyApp theApp = new MyApp (args);
            theApp.enterEventDispatcher();
        }
    
        public MyApp(String [] args) {
            this.invokeLater(new Runnable() {
                public void run() {
                    // In here.....
                }
            });
        }
    

    Note, this is just a theory, I have not tested this.

  • applicationContext remains "null" after using the custom url scheme to launch the app

    Hello

    I am currently working on a DPS application for a customer who wishes to use its own authentication system.

    The client system is implemented so that they send the valid token to a URI with a custom method.

    By setting the same pattern custom in my app DPS constructor, I can get the app from the login window.

    What is described in the library of DPS & Api store 2.32 documentation, I understand that

    " adobeDPS.configurationService.applicationContext must contain several variables associated to how the viewer was started or enabled:" ","this class represents the context under which the application is launched '


    However, in my application when I try to see what contains the applicationContext, the object is always 'null '. It doesn't matter if I started the application by clicking on its icon or if it was launched using the custom uri scheme.


    Is this a bug or am I missing something here? I really need this token.

    Hello

    After being stuck for a while trying to work with the url of my client for usage, I finally tested it with a modified version and have found the cause of the problem.

    Work of first information provided by a colleague who was apparently not detailed enough for the customer asked me to use a url of the form App. scheme://auth/#token=...

    It turns out that this kind of url can start or bring the app to the front, but applicationContext remains empty.

    My tests using a url in the same form as you suggested (eg. app. scheme://v1/slot/library) can trigger the app or transmit data.

    The documentation available in the SDK library & shop and article on how to use a custom template is very vague on what formats link actually works, and how we can vary with it.

    A breakdown of official links to pieces, that the parties do and what items can be modified (for example ' / appstate') within the API documentation would be a great help for developers, I think.

    Kind regards

    Lorin

  • Security error to access the url

    Hello experts

    I came across very good and it seems easy enough to solve the problem.

    I developed advance right application (film guide) which reads 2 FLOW RSS (that of the chain of cinemas) and that of film criticism Web site. It allows users to check what movies are shown in particular (as to which dates and times) film and besides it gets critical review (I personally hate to waste time on some really bad movies).

    This application has been developed for my own use, but I decided to upload it to the public server so I can access it from anywhere.

    The first attempt to run application on the server (it works perfectly fine on my laptop) I got following error:

    Security error to access the url
    Destination: DefaultHTTP

    I thought, just enough, need to add more entries to my file crossdomain.xml (already created).

    So the file crossdomain.xml currently looks like this:

    <? XML version = "1.0"? >
    < cross-domain-policy >
    < site permitted-cross-domain-policies of control = 'all' / >
    "< allow-access-from domain ="http://www.morzech.myzen.co.uk"to-ports =" * "/ >"
    "< allow-http-request-headers-from domain ="http://www.morzech.myzen.co.uk"headers =" * "/ >"
    "< allow-http-request-headers-from domain ="http://www.cineworld.co.uk"headers =" * "/ >"
    "< allow-http-request-headers-from domain ="http://www.rottentomatoes.com"headers =" * "/ >"
    < / cross-domain-policy >

    You can find my application under the following URL:

    http://www.morzech.myZen.co.UK/development/CinemaGuide/CinemaGuideSE.html

    2 FLOW RSS, that I am importing are:

    http://www.Cineworld.co.UK/syndication/all-performances.XML

    http://www.rottentomatoes.com/Syndication/RSS/in_theaters.XML

    Please share your ideas on what I might be doing wrong (or missing).

    Concerning

    Michael

    You can use a proxy server

  • &amp; quot; Security for access to the url error &amp; quot;

    Hello
    I have two problems,
    an I get error of scripts cross-domain as indicated in the title of the message is to say "security to access the url error.
    I tried to access using webserice and http service requesta and a web service request. I kept getting the same error. I tried to put the crossdomain.xml file in the root of the server and he had no luck either. Any suggestions would be helpful.
    one of the operations in the wsdl file is called getlookupvalues, and it takes 4 parameters, database, username, password and lookupid. the lookupID is a GUID.
    When I tried to create a request to getlookupvalues with the above parameters that it kept giving me compile erros saying incompatible correlation of type guid and string. Think is because I am past the guid as a string. A way to pass a guid as a guid instead of a string?

    Thank you very much

    Aerts

    Sort the cross-domain problem using mx:Webservice, and not a httpservice.

  • AIR iOS URL scheme

    I'm developing an AIR for iOS app for my client to run on an iPad, and my application should be able to launch other applications using a URL scheme and also to be launched by another application, by receiving a URL scheme by it. What I read, it seems that AIR for iOS apps can receive and respond to URL patterns, but they are unable to send URL patterns to launch other applications, due to security restrictions.

    Anyone know if it is possible for send and receive URL patterns?

    Yes, you can.

    Open installed "Wikitude" app can be done via this script

    import flash.events.MouseEvent;

    btn.addEventListener(MouseEvent.CLICK, callURL);

    function callURL(e:MouseEvent):void{
        navigateToURL(new URLRequest("wikitude://"));
    }

    Likewise, you can open your app from any other. In the example above Wikitude app is URI id. The same below the iPadARIconAppB

    Here is the part of the descriptor of the Application - my old project xml.xml:

    UIDeviceFamily

    1

    2

    CFBundleURLTypes

    CFBundleURLName

    com.camel.geo.iPadARIconAppB.iPadARIconAppB - schema

    CFBundleURLSchemes

    iPadARIconAppB

    UIApplicationExitsOnSuspend

    ]]>

    standard

    You must replace CFBundleURLName by your app in my sample ID and CFBundleURLSchemes put your own application name.

    If you want to open your application to any other - you must open "iPadARIconAppB://" and if you pass params - just "iPadARIconAppB:/ / myparams" and read via Invoke in Adobe Air. "

    The air is great and allow a lot of things

Maybe you are looking for