Tuesday 15 September 2015

java - Authentication and Session management with Apache CXF DOSGi -


I have a client - server application that uses CCF dosage [1] Now I certify clients to the server And I want to create a session for the customer. The client will have a cookie that is used to authenticate once the service to be used. I would like to know what is the best way to use an HTTP session for the server and what is the best way to authenticate cookies once the client finally.

I was thinking of creating a custom session object once the application level is certified and sends the cookie object to the client. Therefore, when the client reaches the service practices, then it will pass the cookie as an argument. Customers will be valid in each service method. But I do not think this is the best way to handle this matter, because in every service method, there must be a different logic for passing the cookie.

When I was goggling, I came upon it [2]. Is it possible to get "Website Consets" in service in Doji? Even if I receive it, how do I store the cookie at the customer's end and will ensure that the client sends the cookie to every next web service call? [2]

[2]

Any help is highly appreciated. Thank you. You can use a custom intent to control authentication. Actually, an intention is a CXF feature that applies to Dosgis on the website. You can create a facility in a separate bundle and then publish it with a special property for your name: see.

In a project we created a feature that reads the credential reference to the ThreadLocal and stored Credentials thereby filling the CXF authentication. You will have to store the credentials once in the threadlocal at the beginning of the application and all the calls have to be done.

There is currently no ordinary documentation or example in this case, but I am planning to make it nearby, certification is a common problem in the form of future. I am planning to use Shirorrow as a certification framework and write a normal adapter for CXF. As soon as I got it ready, I would add a comment or a second answer. During this time you can try to do it yourself

No comments:

Post a Comment