Jakarta Authentication with Angular front using Glassfish app server and MSSQL DB

Viewed 46

I am pretty new in web development world. I want to create an authentication for my full-stack application. I use Angular 13 as front, Jakarta 9 with Glassfish app server and MSSQL DB. I want to create an authentication on the above configurations but I don't know from where to start. I didn't find any documentation that would help an unexperienced user like me.

Can you please explain what I have to do, or can you give me some tutorials from where I can learn? I want to do a simple authentication, not using oauth2 or other protocols. From the front-side the users input credential and they are checked in the DB. Something like JDBC Authentication from Spring.

1 Answers

You can probably start with using the BASIC authentication mechanism and the Database identity store.

For example:

@BasicAuthenticationMechanismDefinition(
    realmName="my realm"
)
@DatabaseIdentityStoreDefinition(
    dataSourceLookup = "java:global/MyDS",
    callerQuery = "select password from caller where name = ?",
    groupsQuery = "select group_name from caller_groups where caller_name = ?",
    hashAlgorithm = Pbkdf2PasswordHash.class,
    priorityExpression = "100",
    hashAlgorithmParameters = {
        "Pbkdf2PasswordHash.Iterations=3072",
        "${applicationConfig.dyna}"
    } // just for test / example
)
@ApplicationScoped
@Named
public class ApplicationConfig {

    public String[] getDyna() {
        return new String[]{"Pbkdf2PasswordHash.Algorithm=PBKDF2WithHmacSHA512", "Pbkdf2PasswordHash.SaltSizeBytes=64"};
    }

} 

Note that the values for the Database config are examples, and you can tune them in whatever way you like. You also don't need the expression referring to the class method, which is just given as an example too.

For fully working examples with an included test, see:

https://github.com/jakartaee/security/tree/master/tck/app-mem-basic https://github.com/jakartaee/security/tree/master/tck/app-db

Related