🟠Basic Authentication:
Отправка имени пользователя и пароля в Base64. Конфигурация в
web.xml:<login-config>
<auth-method>BASIC</auth-method>
<realm-name>Protected Area</realm-name>
</login-config>
🟠Digest Authentication:
Хеширование учетных данных для безопасности. Конфигурация в
web.xml:<login-config>
<auth-method>DIGEST</auth-method>
<realm-name>Protected Area</realm-name>
</login-config>
🟠Form-based Authentication:
Использование HTML-форм для ввода учетных данных. Конфигурация в
web.xml:<login-config>
<auth-method>FORM</auth-method>
<form-login-config>
<form-login-page>/login.jsp</form-login-page>
<form-error-page>/error.jsp</form-error-page>
</form-login-config>
</login-config>
🟠Client Certificate Authentication:
Использование клиентских SSL-сертификатов. Конфигурация в
web.xml:<login-config>
<auth-method>CLIENT-CERT</auth-method>
</login-config>
🟠Custom Authentication:
Реализация собственной логики через сервлеты и фильтры. Пример фильтра:
public class AuthenticationFilter implements Filter {
public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain)
throws IOException, ServletException {
HttpServletRequest httpRequest = (HttpServletRequest) request;
HttpSession session = httpRequest.getSession(false);
if (session != null && session.getAttribute("user") != null) {
chain.doFilter(request, response);
} else {
httpRequest.getRequestDispatcher("/login.jsp").forward(request, response);
}
}
}Ставь 👍 и забирай 📚 Базу знаний