<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security managed by the web container of webService client. in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/security-managed-by-the-web-container-of-webservice-client/m-p/56586#M34244</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We have set stuff up with Siteminder and IChains to pick up the user from the "x-user" HTTP header. I have only tested this for the UI authentication, with normal login disabled, and only use with SSL between the front end and the trusting alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;There is no reason why it can not be done for web services.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am not sure if it is as simple as wiring up the NovellIChainsHTTPRequestAuthenticationFilter for web services, setting the appropriate header with the user info for all web service calls, and then let the filter do the work. I have not tested this.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If authentication is all external, and you secure all the access routes or disable them, you could use the authentication component that allows or denies all users. So in our case you could allow all - then you do not need to know the password. This will work for web service authentication without changing any of the filters. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So if you are all web service you can use the above - if you want to use more then try the filter approach.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Feb 2007 18:18:26 GMT</pubDate>
    <dc:creator>andy</dc:creator>
    <dc:date>2007-02-21T18:18:26Z</dc:date>
    <item>
      <title>Security managed by the web container of webService client.</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/security-managed-by-the-web-container-of-webservice-client/m-p/56585#M34243</link>
      <description>Hello,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is there a way to obtain a solution where the transfer of the user account (userId, password) for the initial connection to the webService layer is managed by the web container of the calling web application?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; What I try to do is to transmit user credentials from my web application</description>
      <pubDate>Thu, 15 Feb 2007 12:43:02 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/security-managed-by-the-web-container-of-webservice-client/m-p/56585#M34243</guid>
      <dc:creator>anweber</dc:creator>
      <dc:date>2007-02-15T12:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Security managed by the web container of webService client.</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/security-managed-by-the-web-container-of-webservice-client/m-p/56586#M34244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We have set stuff up with Siteminder and IChains to pick up the user from the "x-user" HTTP header. I have only tested this for the UI authentication, with normal login disabled, and only use with SSL between the front end and the trusting alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;There is no reason why it can not be done for web services.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am not sure if it is as simple as wiring up the NovellIChainsHTTPRequestAuthenticationFilter for web services, setting the appropriate header with the user info for all web service calls, and then let the filter do the work. I have not tested this.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If authentication is all external, and you secure all the access routes or disable them, you could use the authentication component that allows or denies all users. So in our case you could allow all - then you do not need to know the password. This will work for web service authentication without changing any of the filters. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So if you are all web service you can use the above - if you want to use more then try the filter approach.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Feb 2007 18:18:26 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/security-managed-by-the-web-container-of-webservice-client/m-p/56586#M34244</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2007-02-21T18:18:26Z</dc:date>
    </item>
  </channel>
</rss>

