Save This Page
Home » JBoss-5.1.0 » org » jboss » security » plugins » [javadoc | source]
public class: JaasSecurityManager [javadoc | source]

All Implemented Interfaces:
    RealmMapping, SubjectSecurityManager, KernelControllerContextAware, ServiceMBean, MBeanRegistration, NotificationEmitter

Direct Known Subclasses:

The JaasSecurityManager is responsible both for authenticating credentials associated with principals and for role mapping. This implementation relies on the JAAS LoginContext/LoginModules associated with the security domain name associated with the class for authentication, and the context JAAS Subject object for role mapping.
Fields inherited from org.jboss.system.ServiceMBeanSupport:
SERVICE_CONTROLLER_SIG,  log,  server,  serviceName
 public JaasSecurityManager() 
 public JaasSecurityManager(String securityDomain,
    CallbackHandler handler) 
    Creates a JaasSecurityManager for with a securityDomain name of that given by the 'securityDomain' argument.
    securityDomain - the name of the security domain
    handler - the JAAS callback handler instance to use
    UndeclaredThrowableException - thrown if handler does not implement a setSecurityInfo(Princpal, Object) method
    exception: UndeclaredThrowableException - thrown if handler does not implement a setSecurityInfo(Princpal, Object) method
Method from Summary:
doesUserHaveRole,   flushCache,   getActiveSubject,   getPrincipal,   getSecurityDomain,   getTargetPrincipal,   getUserRoles,   isValid,   isValid,   setCachePolicy,   setDeepCopySubjectOption
Methods from org.jboss.system.ServiceMBeanSupport:
create,   createService,   destroy,   destroyService,   getDeploymentInfo,   getLog,   getName,   getNextNotificationSequenceNumber,   getObjectName,   getServer,   getServiceName,   getState,   getStateString,   jbossInternalCreate,   jbossInternalDescription,   jbossInternalDestroy,   jbossInternalLifecycle,   jbossInternalStart,   jbossInternalStop,   pojoChange,   pojoCreate,   pojoDestroy,   pojoStart,   pojoStop,   postDeregister,   postRegister,   preDeregister,   preRegister,   setKernelControllerContext,   start,   startService,   stop,   stopService,   unsetKernelControllerContext
Methods from
addNotificationListener,   getNotificationInfo,   handleNotification,   nextNotificationSequenceNumber,   removeNotificationListener,   removeNotificationListener,   sendNotification
Methods from java.lang.Object:
clone,   equals,   finalize,   getClass,   hashCode,   notify,   notifyAll,   toString,   wait,   wait,   wait
Method from Detail:
 public boolean doesUserHaveRole(Principal principal,
    Set<Principal> rolePrincipals) 
    Does the current Subject have a role(a Principal) that equates to one of the role names. This method obtains the Group named 'Roles' from the principal set of the currently authenticated Subject as determined by the SecurityAssociation.getSubject() method and then creates a SimplePrincipal for each name in roleNames. If the role is a member of the Roles group, then the user has the role. This requires that the caller establish the correct SecurityAssociation subject prior to calling this method. In the past this was done as a side-effect of an isValid() call, but this is no longer the case.
 public  void flushCache() 
    Not really used anymore as the security manager service manages the security domain authentication caches.
 public Subject getActiveSubject() 
    Get the currently authenticated Subject. This is a thread local property shared across all JaasSecurityManager instances.
 public Principal getPrincipal(Principal principal) 
    Map the argument principal from the deployment environment principal to the developer environment. This is called by the EJB context getCallerPrincipal() to return the Principal as described by the EJB developer domain.
 public String getSecurityDomain() 
    Get the name of the security domain associated with this security mgr.
 public Principal getTargetPrincipal(Principal anotherDomainPrincipal,
    Map<String, Object> contextMap) 
 public Set<Principal> getUserRoles(Principal principal) 
    Return the set of domain roles the current active Subject 'Roles' group found in the subject Principals set.
 public boolean isValid(Principal principal,
    Object credential) 
    Validate that the given credential is correct for principal. This returns the value from invoking isValid(principal, credential, null).
 public boolean isValid(Principal principal,
    Object credential,
    Subject activeSubject) 
    Validate that the given credential is correct for principal. This first will check the current CachePolicy object if one exists to see if the user's cached credentials match the given credential. If there is no credential cache or the cache information is invalid or does not match, the user is authenticated against the JAAS login modules configured for the security domain.
 public  void setCachePolicy(CachePolicy domainCache) 
    The domainCache is typically a shared object that is populated by the login code(LoginModule, etc.) and read by this class in the isValid() method.
 public  void setDeepCopySubjectOption(Boolean flag) 
    Flag to specify if deep copy of subject sets needs to be enabled