I want to access the web page view1.jsp
The web.xml file is
<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://xmlns.jcp.org/xml/ns/javaee" xsi:schemaLocation="http://xmlns.jcp.org/xml/ns/javaee http://xmlns.jcp.org/xml/ns/javaee/web-app_3_1.xsd" id="WebApp_ID" version="3.1">
<display-name>library management system</display-name>
<login-config>
<auth-method>FORM</auth-method>
<realm-name>jaascon</realm-name>
<form-login-config>
<form-login-page>/login.jsp</form-login-page>
<form-error-page>/error.jsp</form-error-page>
</form-login-config>
</login-config>
<security-role>
<role-name>*</role-name>
</security-role>
<security-constraint>
<web-resource-collection>
<web-resource-name>test</web-resource-name>
<url-pattern>/view1.jsp</url-pattern>
<http-method>POST</http-method>
<http-method>GET</http-method>
</web-resource-collection>
<auth-constraint>
<role-name>*</role-name>
</auth-constraint>
</security-constraint>
</web-app>
The login module is
package p1;
import java.io.IOException;
import java.util.ArrayList;
import java.util.List;
import java.util.Map;
import javax.security.auth.Subject;
import javax.security.auth.callback.Callback;
import javax.security.auth.callback.CallbackHandler;
import javax.security.auth.callback.NameCallback;
import javax.security.auth.callback.PasswordCallback;
import javax.security.auth.callback.UnsupportedCallbackException;
import javax.security.auth.login.FailedLoginException;
import javax.security.auth.login.LoginException;
import javax.security.auth.spi.LoginModule;
import p1.cbhandler;
import p1.roleprincipal;
import p1.userprincipal;
import java.sql.*;
public class lgmodule implements LoginModule {
private CallbackHandler handler;
private Subject subject;
private userprincipal userPrincipal;
private roleprincipal rolePrincipal;
private String login;
private ArrayList<String> userGroups =new ArrayList<String>();
static private String name;
static private String password;
static private Map options;
static boolean f=false;
@Override
public void initialize(Subject subject, CallbackHandler handler,
Map<String, ?> sharedState, Map<String, ?> options) {
this.subject = subject;
this.handler = handler;
this.options=options;
}
@Override
public boolean login() throws LoginException{
System.setProperty("java.security.auth.login.config", "C:/apache-tomcat-9.0.62/webapps/test/jaascon.config");
if (handler == null){
throw new LoginException("Error: no CallbackHandler available " + "to garner authentication information from the user");
}
ArrayList<String> l=new ArrayList<String>();
l.add("user1");
l.add("user2");
Callback[] cbarray=new Callback[2];
cbarray[0]=new NameCallback("username: ");
cbarray[1]=new PasswordCallback("password: ",false);
try {
handler.handle(cbarray);
}
catch(Exception e) {
e.printStackTrace();
}
name=(String)((NameCallback) cbarray[0]).getName();
password=new String(((PasswordCallback) cbarray[1]).getPassword());
String sql ="select username from usertable where username=? and password=?";
String sql1="select rolename from rolestable where username=?";
ResultSet rs = null,rs1=null;
PreparedStatement stmt = null,stmt1=null;
boolean b=false;
String s="";
try {
Class.forName("com.mysql.cj.jdbc.Driver");
Connection con=DriverManager.getConnection("jdbc:mysql://localhost:3306/mydb" ,"root","Dinesh@1972002");
stmt = con.prepareStatement(sql);
stmt.setString(1, name);
stmt.setString(2, new String(password));
rs = stmt.executeQuery();
stmt1=con.prepareStatement(sql1);
stmt1.setString(1,name);
rs1=stmt1.executeQuery();
b=rs1.next();
s=rs1.getString(1);
if (rs.next()) {
f=true;
userGroups.add(s);
}
else {
System.out.println("authentication failure");
//throw new FailedLoginException(rs.getString(1));
}
} catch (Exception e) {
throw new LoginException("Error when loading user from the database " +e
);
}
return f;
}
@Override
public boolean commit() throws LoginException {
userPrincipal = new userprincipal(name);
subject.getPrincipals().add(userPrincipal);
if (userGroups != null && userGroups.size() > 0) {
for (String groupName : userGroups) {
rolePrincipal = new roleprincipal(groupName);
subject.getPrincipals().add(rolePrincipal);
}
}
return true;
}
@Override
public boolean abort() throws LoginException {
return f;
}
@Override
public boolean logout() throws LoginException {
subject.getPrincipals().remove(userPrincipal);
subject.getPrincipals().remove(rolePrincipal);
return true;
}
}
The callback handler file is
package p1;
import java.io.IOException;
import javax.security.auth.callback.Callback;
import javax.security.auth.callback.CallbackHandler;
import javax.security.auth.callback.NameCallback;
import javax.security.auth.callback.PasswordCallback;
import javax.security.auth.callback.UnsupportedCallbackException;
public class cbhandler implements CallbackHandler {
private String username = null;
private String password = null;
public cbhandler(String username, String password) {
this.username = username;
this.password = password;
}
@Override
public void handle(Callback[] callbacks) throws IOException,
UnsupportedCallbackException {
//System.setProperty("java.security.auth.login.config","C:/apache-tomcat-9.0.62/webapps/test/jaascon.config");
for (int i = 0; i < callbacks.length; i++) {
if (callbacks[i] instanceof NameCallback) {
NameCallback nameCallback = (NameCallback) callbacks[i];
nameCallback.setName(username);
} else if (callbacks[i] instanceof PasswordCallback) {
PasswordCallback passwordCallback = (PasswordCallback) callbacks[i];
passwordCallback.setPassword(password.toCharArray());
} else {
throw new UnsupportedCallbackException(callbacks[i], "The submitted Callback is unsupported");
}
}
}
}
The login.jsp page is
<!DOCTYPE html>
<html>
<head>
<style>
div{
margin: 100px;
padding: 100px;
background-color: dodgerblue;
}
</style>
</head>
<body>
<h1 style="display: flex;justify-content: center;">Login</h1>
<div>
<div style="position:relative;left:100px">
<form name="loginform" action="j_security_check" method="Post">
enter user name:<input type="text" name="j_username"><br>
enter password:<input type="password" name="j_password"><br>
<input name="login" type="submit" value="LOGIN" id="submit" class="button blue">
</div>
</div>
</form>
The configuration file(jaascon.config) is
jaascon{
p1.lgmodule required
debug=true;
};
I want to authenticate my webapp using java authentication and authorization system(jaas). How to send username and password to callback handler and how the login method will be invoked?.