Initial commit.

This commit is contained in:
Ben Alex
2004-03-16 23:57:17 +00:00
commit 35fe1e7b73
267 changed files with 17812 additions and 0 deletions

View File

@@ -0,0 +1,6 @@
classes
reports
temporary
containers
build.properties

231
integration-test/build.xml Normal file
View File

@@ -0,0 +1,231 @@
<?xml version="1.0"?>
<!--
Build file for running container integration tests.
$Id$
-->
<project name="acegi-security-integration-tests" default="usage" basedir=".">
<property file="build.properties"/>
<property file="project.properties"/>
<path id="qa-portalpath">
<fileset dir="${dist.lib.dir}">
<include name="acegi-security-spring.jar"/>
</fileset>
<fileset dir="${lib.dir}">
<include name="**/*.jar"/>
</fileset>
<fileset dir="${httpunit.lib.dir}">
<include name="**/*.jar"/>
</fileset>
</path>
<path id="jalopy-classpath">
<fileset dir="${lib.dir}/jalopy">
<include name="**/*.jar"/>
</fileset>
</path>
<target name="usage">
<echo message=""/>
<echo message="${name} build file"/>
<echo message="------------------------------------------------------"/>
<echo message=""/>
<echo message="Among the available targets are:"/>
<echo message=""/>
<echo message="clean --> deletes output directories"/>
<echo message="unzip --> unzips each container into file system"/>
<echo message="tests --> unzips each container and runs all tests"/>
<echo message="tests-jetty --> runs the integration tests with Jetty"/>
<echo message="tests-jboss --> runs the integration tests with JBoss"/>
<echo message="tests-catalina --> runs the integration tests with Catalina"/>
<echo message=""/>
<echo message="Each tests-xxxx target assumes the container is unzipped"/>
<echo message=""/>
<echo message="BE SURE TO CHECK REPORTS DIRECTORY FOR RESULTS OF TESTS!"/>
<echo message=" *** The script does NOT halt if a test fails ***"/>
<echo message=""/>
</target>
<target name="clean" description="Clean all output dirs">
<delete dir="${build.dir}"/>
<delete dir="${tmp.dir}"/>
<delete dir="${reports.dir}"/>
</target>
<target name="buildtests" depends="" description="Compile test source tree Java files into class files">
<mkdir dir="${build.dir}"/>
<javac destdir="${build.dir}" target="1.3" debug="${debug}"
deprecation="false" optimize="false" failonerror="true">
<src path="${src.dir}"/>
<classpath refid="qa-portalpath"/>
</javac>
</target>
<target name="format" description="Formats all project source code">
<taskdef name="jalopy" classname="de.hunsicker.jalopy.plugin.ant.AntPlugin">
<classpath refid="jalopy-classpath"/>
</taskdef>
<jalopy fileformat="unix"
convention="${jalopy.xml}"
history="file"
historymethod="adler32"
loglevel="error"
threads="2"
classpathref="qa-portalpath">
<fileset dir="${src.dir}">
<include name="**/*.java"/>
</fileset>
</jalopy>
</target>
<target name="tests" depends="clean,unzip,tests-jetty,tests-catalina,tests-jboss" description="Run all integration tests">
<echo message="BE SURE TO CHECK REPORTS DIRECTORY FOR RESULTS OF TESTS!"/>
</target>
<target name="tests-jetty" depends="buildtests" description="Runs Jetty integration tests">
<copy file="${config.dir}/jetty-4.2.18/jetty.xml" todir="${tmp.dir}/jetty-4.2.18/etc" overwrite="true"/>
<copy file="${acegisecurity.xml}" todir="${tmp.dir}/jetty-4.2.18/etc" overwrite="true"/>
<copy file="${dist.lib.dir}/acegi-security-jetty-ext.jar" todir="${tmp.dir}/jetty-4.2.18/ext" overwrite="true"/>
<copy file="${lib.dir}/aop-alliance/aopalliance.jar" todir="${tmp.dir}/jetty-4.2.18/ext" overwrite="true"/>
<copy file="${lib.dir}/jakarta-commons/commons-logging.jar" todir="${tmp.dir}/jetty-4.2.18/ext" overwrite="true"/>
<copy file="${lib.dir}/spring/spring.jar" todir="${tmp.dir}/jetty-4.2.18/ext" overwrite="true"/>
<copy file="${contacts.war}" todir="${tmp.dir}/jetty-4.2.18/webapps" overwrite="true"/>
<parallel>
<java fork="true" dir="${tmp.dir}/jetty-4.2.18/" classpath="${tmp.dir}/jetty-4.2.18/start.jar" classname="org.mortbay.start.Main">
</java>
<sequential>
<waitfor maxwait="60" maxwaitunit="second" checkevery="500" checkeveryunit="millisecond">
<http url="http://localhost:8080/contacts" />
</waitfor>
<delete dir="${reports.dir}/jetty-4.2.18"/>
<mkdir dir="${reports.dir}/jetty-4.2.18"/>
<junit printsummary="yes" haltonfailure="no">
<classpath location="${build.dir}"/>
<classpath refid="qa-portalpath"/>
<formatter type="plain"/>
<batchtest fork="yes" todir="${reports.dir}/jetty-4.2.18">
<fileset dir="${build.dir}" includes="${test.includes}" excludes="${test.excludes}"/>
</batchtest>
</junit>
<java fork="true" dir="${tmp.dir}/jetty-4.2.18/" classpath="${tmp.dir}/jetty-4.2.18/stop.jar" classname="org.mortbay.stop.Main"/>
</sequential>
</parallel>
</target>
<target name="tests-catalina" depends="buildtests" description="Runs Catalina integration tests">
<delete dir="${tmp.dir}/jakarta-tomcat-5.0.19/webapps/contacts"/>
<copy file="${config.dir}/catalina-5.0.19/server.xml" todir="${tmp.dir}/jakarta-tomcat-5.0.19/conf" overwrite="true"/>
<copy file="${acegisecurity.xml}" todir="${tmp.dir}/jakarta-tomcat-5.0.19/conf" overwrite="true"/>
<copy file="${dist.lib.dir}/acegi-security-catalina-server.jar" todir="${tmp.dir}/jakarta-tomcat-5.0.19/server/lib" overwrite="true"/>
<copy file="${dist.lib.dir}/acegi-security-catalina-common.jar" todir="${tmp.dir}/jakarta-tomcat-5.0.19/common/lib" overwrite="true"/>
<copy file="${lib.dir}/aop-alliance/aopalliance.jar" todir="${tmp.dir}/jakarta-tomcat-5.0.19/common/lib" overwrite="true"/>
<copy file="${lib.dir}/spring/spring.jar" todir="${tmp.dir}/jakarta-tomcat-5.0.19/common/lib" overwrite="true"/>
<copy file="${contacts.war}" todir="${tmp.dir}/jakarta-tomcat-5.0.19/webapps" overwrite="true"/>
<property name="tomcat.home" value="${tmp.dir}/jakarta-tomcat-5.0.19"/>
<parallel>
<java fork="true" classname="org.apache.catalina.startup.Bootstrap" dir="${tomcat.home}">
<jvmarg value="-Dcatalina.home=${tomcat.home}"/>
<arg value="start"/>
<classpath>
<pathelement path="${java.home}/../lib/tools.jar"/>
<fileset dir="${tomcat.home}">
<include name="bin/bootstrap.jar"/>
</fileset>
</classpath>
</java>
<sequential>
<waitfor maxwait="60" maxwaitunit="second" checkevery="500" checkeveryunit="millisecond">
<http url="http://localhost:8080/contacts" />
</waitfor>
<delete dir="${reports.dir}/jakarta-tomcat-5.0.19"/>
<mkdir dir="${reports.dir}/jakarta-tomcat-5.0.19"/>
<junit printsummary="yes" haltonfailure="no">
<classpath location="${build.dir}"/>
<classpath refid="qa-portalpath"/>
<formatter type="plain"/>
<batchtest fork="yes" todir="${reports.dir}/jakarta-tomcat-5.0.19">
<fileset dir="${build.dir}" includes="${test.includes}" excludes="${test.excludes}"/>
</batchtest>
</junit>
<java fork="true" classname="org.apache.catalina.startup.Bootstrap" dir="${tomcat.home}">
<jvmarg value="-Dcatalina.home=${tomcat.home}"/>
<arg value="stop"/>
<classpath>
<pathelement path="${java.home}/../lib/tools.jar"/>
<fileset dir="${tomcat.home}">
<include name="bin/bootstrap.jar"/>
</fileset>
</classpath>
</java>
</sequential>
</parallel>
</target>
<target name="tests-jboss" depends="buildtests" description="Runs JBoss integration tests">
<copy file="${config.dir}/jboss-3.2.3/login-config.xml" todir="${tmp.dir}/jboss-3.2.3/server/default/conf" overwrite="true"/>
<copy file="${acegisecurity.xml}" todir="${tmp.dir}/jboss-3.2.3/server/default/conf" overwrite="true"/>
<copy file="${dist.lib.dir}/acegi-security-jboss-lib.jar" todir="${tmp.dir}/jboss-3.2.3/server/default/lib" overwrite="true"/>
<copy file="${lib.dir}/aop-alliance/aopalliance.jar" todir="${tmp.dir}/jboss-3.2.3/server/default/lib" overwrite="true"/>
<copy file="${lib.dir}/spring/spring.jar" todir="${tmp.dir}/jboss-3.2.3/server/default/lib" overwrite="true"/>
<copy file="${contacts.war}" todir="${tmp.dir}/jboss-3.2.3/server/default/deploy" overwrite="true"/>
<parallel>
<java fork="yes" classname="org.jboss.Main" dir="${tmp.dir}/jboss-3.2.3">
<classpath>
<pathelement path="${java.home}/../lib/tools.jar"/>
<pathelement path="${tmp.dir}/jboss-3.2.3/bin/run.jar"/>
</classpath>
</java>
<sequential>
<waitfor maxwait="60" maxwaitunit="second" checkevery="500" checkeveryunit="millisecond">
<http url="http://localhost:8080/contacts" />
</waitfor>
<delete dir="${reports.dir}/jboss-3.2.3"/>
<mkdir dir="${reports.dir}/jboss-3.2.3"/>
<junit printsummary="yes" haltonfailure="no">
<classpath location="${build.dir}"/>
<classpath refid="qa-portalpath"/>
<formatter type="plain"/>
<batchtest fork="yes" todir="${reports.dir}/jboss-3.2.3">
<fileset dir="${build.dir}" includes="${test.includes}" excludes="${test.excludes}"/>
</batchtest>
</junit>
<java fork="yes" classname="org.jboss.Shutdown" dir="${tmp.dir}/jboss-3.2.3">
<arg value="--shutdown"/>
<classpath>
<pathelement path="${tmp.dir}/jboss-3.2.3/bin/shutdown.jar"/>
</classpath>
</java>
</sequential>
</parallel>
</target>
<target name="unzip" depends="unzip-jetty,unzip-catalina,unzip-jboss" description="Unzip all containers"/>
<target name="unzip-jetty" depends="" description="Unzip Jetty container">
<delete dir="${tmp.dir}/Jetty-4.2.18"/>
<mkdir dir="${tmp.dir}/Jetty-4.2.18"/>
<unzip src="${containers.dir}/Jetty-4.2.18-all.zip" dest="${tmp.dir}"/>
</target>
<target name="unzip-catalina" depends="" description="Unzip Catalina container">
<delete dir="${tmp.dir}/jakarta-tomcat-5.0.19"/>
<mkdir dir="${tmp.dir}/jakarta-tomcat-5.0.19"/>
<unzip src="${containers.dir}/jakarta-tomcat-5.0.19.zip" dest="${tmp.dir}"/>
</target>
<target name="unzip-jboss" depends="" description="Unzip JBoss container">
<delete dir="${tmp.dir}/jboss-3.2.3"/>
<mkdir dir="${tmp.dir}/jboss-3.2.3"/>
<unzip src="${containers.dir}/jboss-3.2.3.zip" dest="${tmp.dir}"/>
</target>
</project>

View File

@@ -0,0 +1,366 @@
<!-- Example Server Configuration File -->
<!-- Note that component elements are nested corresponding to their
parent-child relationships with each other -->
<!-- A "Server" is a singleton element that represents the entire JVM,
which may contain one or more "Service" instances. The Server
listens for a shutdown command on the indicated port.
Note: A "Server" is not itself a "Container", so you may not
define subcomponents such as "Valves" or "Loggers" at this level.
-->
<Server port="8005" shutdown="SHUTDOWN" debug="0">
<!-- Comment these entries out to disable JMX MBeans support -->
<!-- You may also configure custom components (e.g. Valves/Realms) by
including your own mbean-descriptor file(s), and setting the
"descriptors" attribute to point to a ';' seperated list of paths
(in the ClassLoader sense) of files to add to the default list.
e.g. descriptors="/com/myfirm/mypackage/mbean-descriptor.xml"
-->
<Listener className="org.apache.catalina.mbeans.ServerLifecycleListener"
debug="0"/>
<Listener className="org.apache.catalina.mbeans.GlobalResourcesLifecycleListener"
debug="0"/>
<!-- Global JNDI resources -->
<GlobalNamingResources>
<!-- Test entry for demonstration purposes -->
<Environment name="simpleValue" type="java.lang.Integer" value="30"/>
<!-- Editable user database that can also be used by
UserDatabaseRealm to authenticate users -->
<Resource name="UserDatabase" auth="Container"
type="org.apache.catalina.UserDatabase"
description="User database that can be updated and saved">
</Resource>
<ResourceParams name="UserDatabase">
<parameter>
<name>factory</name>
<value>org.apache.catalina.users.MemoryUserDatabaseFactory</value>
</parameter>
<parameter>
<name>pathname</name>
<value>conf/tomcat-users.xml</value>
</parameter>
</ResourceParams>
</GlobalNamingResources>
<!-- A "Service" is a collection of one or more "Connectors" that share
a single "Container" (and therefore the web applications visible
within that Container). Normally, that Container is an "Engine",
but this is not required.
Note: A "Service" is not itself a "Container", so you may not
define subcomponents such as "Valves" or "Loggers" at this level.
-->
<!-- Define the Tomcat Stand-Alone Service -->
<Service name="Catalina">
<!-- A "Connector" represents an endpoint by which requests are received
and responses are returned. Each Connector passes requests on to the
associated "Container" (normally an Engine) for processing.
By default, a non-SSL HTTP/1.1 Connector is established on port 8080.
You can also enable an SSL HTTP/1.1 Connector on port 8443 by
following the instructions below and uncommenting the second Connector
entry. SSL support requires the following steps (see the SSL Config
HOWTO in the Tomcat 5 documentation bundle for more detailed
instructions):
* If your JDK version 1.3 or prior, download and install JSSE 1.0.2 or
later, and put the JAR files into "$JAVA_HOME/jre/lib/ext".
* Execute:
%JAVA_HOME%\bin\keytool -genkey -alias tomcat -keyalg RSA (Windows)
$JAVA_HOME/bin/keytool -genkey -alias tomcat -keyalg RSA (Unix)
with a password value of "changeit" for both the certificate and
the keystore itself.
By default, DNS lookups are enabled when a web application calls
request.getRemoteHost(). This can have an adverse impact on
performance, so you can disable it by setting the
"enableLookups" attribute to "false". When DNS lookups are disabled,
request.getRemoteHost() will return the String version of the
IP address of the remote client.
-->
<!-- Define a non-SSL Coyote HTTP/1.1 Connector on port 8080 -->
<Connector port="8080"
maxThreads="150" minSpareThreads="25" maxSpareThreads="75"
enableLookups="false" redirectPort="8443" acceptCount="100"
debug="0" connectionTimeout="20000"
disableUploadTimeout="true" />
<!-- Note : To disable connection timeouts, set connectionTimeout value
to 0 -->
<!-- Note : To use gzip compression you could set the following properties :
compression="on"
compressionMinSize="2048"
noCompressionUserAgents="gozilla, traviata"
compressableMimeType="text/html,text/xml"
-->
<!-- Define a SSL Coyote HTTP/1.1 Connector on port 8443 -->
<!--
<Connector port="8443"
maxThreads="150" minSpareThreads="25" maxSpareThreads="75"
enableLookups="false" disableUploadTimeout="true"
acceptCount="100" debug="0" scheme="https" secure="true"
clientAuth="false" sslProtocol="TLS" />
-->
<!-- Define a Coyote/JK2 AJP 1.3 Connector on port 8009 -->
<Connector port="8009"
enableLookups="false" redirectPort="8443" debug="0"
protocol="AJP/1.3" />
<!-- Define a Proxied HTTP/1.1 Connector on port 8082 -->
<!-- See proxy documentation for more information about using this. -->
<!--
<Connector port="8082"
maxThreads="150" minSpareThreads="25" maxSpareThreads="75"
enableLookups="false"
acceptCount="100" debug="0" connectionTimeout="20000"
proxyPort="80" disableUploadTimeout="true" />
-->
<!-- An Engine represents the entry point (within Catalina) that processes
every request. The Engine implementation for Tomcat stand alone
analyzes the HTTP headers included with the request, and passes them
on to the appropriate Host (virtual host). -->
<!-- You should set jvmRoute to support load-balancing via JK/JK2 ie :
<Engine name="Standalone" defaultHost="localhost" debug="0" jvmRoute="jvm1">
-->
<!-- Define the top level container in our container hierarchy -->
<Engine name="Catalina" defaultHost="localhost" debug="0">
<Realm className="net.sf.acegisecurity.adapters.catalina.CatalinaAcegiUserRealm"
appContextLocation="conf/acegisecurity.xml"
key="my_password" />
<!-- The request dumper valve dumps useful debugging information about
the request headers and cookies that were received, and the response
headers and cookies that were sent, for all requests received by
this instance of Tomcat. If you care only about requests to a
particular virtual host, or a particular application, nest this
element inside the corresponding <Host> or <Context> entry instead.
For a similar mechanism that is portable to all Servlet 2.4
containers, check out the "RequestDumperFilter" Filter in the
example application (the source for this filter may be found in
"$CATALINA_HOME/webapps/examples/WEB-INF/classes/filters").
Request dumping is disabled by default. Uncomment the following
element to enable it. -->
<!--
<Valve className="org.apache.catalina.valves.RequestDumperValve"/>
-->
<!-- Global logger unless overridden at lower levels -->
<Logger className="org.apache.catalina.logger.FileLogger"
prefix="catalina_log." suffix=".txt"
timestamp="true"/>
<!-- Because this Realm is here, an instance will be shared globally -->
<!-- This Realm uses the UserDatabase configured in the global JNDI
resources under the key "UserDatabase". Any edits
that are performed against this UserDatabase are immediately
available for use by the Realm.
<Realm className="org.apache.catalina.realm.UserDatabaseRealm"
debug="0" resourceName="UserDatabase"/> -->
<!-- Comment out the old realm but leave here for now in case we
need to go back quickly -->
<!--
<Realm className="org.apache.catalina.realm.MemoryRealm" />
-->
<!-- Replace the above Realm with one of the following to get a Realm
stored in a database and accessed via JDBC -->
<!--
<Realm className="org.apache.catalina.realm.JDBCRealm" debug="99"
driverName="org.gjt.mm.mysql.Driver"
connectionURL="jdbc:mysql://localhost/authority"
connectionName="test" connectionPassword="test"
userTable="users" userNameCol="user_name" userCredCol="user_pass"
userRoleTable="user_roles" roleNameCol="role_name" />
-->
<!--
<Realm className="org.apache.catalina.realm.JDBCRealm" debug="99"
driverName="oracle.jdbc.driver.OracleDriver"
connectionURL="jdbc:oracle:thin:@ntserver:1521:ORCL"
connectionName="scott" connectionPassword="tiger"
userTable="users" userNameCol="user_name" userCredCol="user_pass"
userRoleTable="user_roles" roleNameCol="role_name" />
-->
<!--
<Realm className="org.apache.catalina.realm.JDBCRealm" debug="99"
driverName="sun.jdbc.odbc.JdbcOdbcDriver"
connectionURL="jdbc:odbc:CATALINA"
userTable="users" userNameCol="user_name" userCredCol="user_pass"
userRoleTable="user_roles" roleNameCol="role_name" />
-->
<!-- Define the default virtual host
Note: XML Schema validation will not work with Xerces 2.2.
-->
<Host name="localhost" debug="0" appBase="webapps"
unpackWARs="true" autoDeploy="true"
xmlValidation="false" xmlNamespaceAware="false">
<!-- Defines a cluster for this node,
By defining this element, means that every manager will be changed.
So when running a cluster, only make sure that you have webapps in there
that need to be clustered and remove the other ones.
A cluster has the following parameters:
className = the fully qualified name of the cluster class
name = a descriptive name for your cluster, can be anything
debug = the debug level, higher means more output
mcastAddr = the multicast address, has to be the same for all the nodes
mcastPort = the multicast port, has to be the same for all the nodes
mcastFrequency = the number of milliseconds in between sending a "I'm alive" heartbeat
mcastDropTime = the number a milliseconds before a node is considered "dead" if no heartbeat is received
tcpThreadCount = the number of threads to handle incoming replication requests, optimal would be the same amount of threads as nodes
tcpListenAddress = the listen address (bind address) for TCP cluster request on this host,
in case of multiple ethernet cards.
auto means that address becomes
InetAddress.getLocalHost().getHostAddress()
tcpListenPort = the tcp listen port
tcpSelectorTimeout = the timeout (ms) for the Selector.select() method in case the OS
has a wakup bug in java.nio. Set to 0 for no timeout
printToScreen = true means that managers will also print to std.out
expireSessionsOnShutdown = true means that
useDirtyFlag = true means that we only replicate a session after setAttribute,removeAttribute has been called.
false means to replicate the session after each request.
false means that replication would work for the following piece of code:
<%
HashMap map = (HashMap)session.getAttribute("map");
map.put("key","value");
%>
replicationMode = can be either 'pooled', 'synchronous' or 'asynchronous'.
* Pooled means that the replication happens using several sockets in a synchronous way. Ie, the data gets replicated, then the request return. This is the same as the 'synchronous' setting except it uses a pool of sockets, hence it is multithreaded. This is the fastest and safest configuration. To use this, also increase the nr of tcp threads that you have dealing with replication.
* Synchronous means that the thread that executes the request, is also the
thread the replicates the data to the other nodes, and will not return until all
nodes have received the information.
* Asynchronous means that there is a specific 'sender' thread for each cluster node,
so the request thread will queue the replication request into a "smart" queue,
and then return to the client.
The "smart" queue is a queue where when a session is added to the queue, and the same session
already exists in the queue from a previous request, that session will be replaced
in the queue instead of replicating two requests. This almost never happens, unless there is a
large network delay.
-->
<!--
When configuring for clustering, you also add in a valve to catch all the requests
coming in, at the end of the request, the session may or may not be replicated.
A session is replicated if and only if all the conditions are met:
1. useDirtyFlag is true or setAttribute or removeAttribute has been called AND
2. a session exists (has been created)
3. the request is not trapped by the "filter" attribute
The filter attribute is to filter out requests that could not modify the session,
hence we don't replicate the session after the end of this request.
The filter is negative, ie, anything you put in the filter, you mean to filter out,
ie, no replication will be done on requests that match one of the filters.
The filter attribute is delimited by ;, so you can't escape out ; even if you wanted to.
filter=".*\.gif;.*\.js;" means that we will not replicate the session after requests with the URI
ending with .gif and .js are intercepted.
-->
<!--
<Cluster className="org.apache.catalina.cluster.tcp.SimpleTcpCluster"
managerClassName="org.apache.catalina.cluster.session.DeltaManager"
expireSessionsOnShutdown="false"
useDirtyFlag="true">
<Membership
className="org.apache.catalina.cluster.mcast.McastService"
mcastAddr="228.0.0.4"
mcastPort="45564"
mcastFrequency="500"
mcastDropTime="3000"/>
<Receiver
className="org.apache.catalina.cluster.tcp.ReplicationListener"
tcpListenAddress="auto"
tcpListenPort="4001"
tcpSelectorTimeout="100"
tcpThreadCount="6"/>
<Sender
className="org.apache.catalina.cluster.tcp.ReplicationTransmitter"
replicationMode="pooled"/>
<Valve className="org.apache.catalina.cluster.tcp.ReplicationValve"
filter=".*\.gif;.*\.js;.*\.jpg;.*\.htm;.*\.html;.*\.txt;"/>
</Cluster>
-->
<!-- Normally, users must authenticate themselves to each web app
individually. Uncomment the following entry if you would like
a user to be authenticated the first time they encounter a
resource protected by a security constraint, and then have that
user identity maintained across *all* web applications contained
in this virtual host. -->
<!--
<Valve className="org.apache.catalina.authenticator.SingleSignOn"
debug="0"/>
-->
<!-- Access log processes all requests for this virtual host. By
default, log files are created in the "logs" directory relative to
$CATALINA_HOME. If you wish, you can specify a different
directory with the "directory" attribute. Specify either a relative
(to $CATALINA_HOME) or absolute path to the desired directory.
-->
<!--
<Valve className="org.apache.catalina.valves.AccessLogValve"
directory="logs" prefix="localhost_access_log." suffix=".txt"
pattern="common" resolveHosts="false"/>
-->
<!-- Logger shared by all Contexts related to this virtual host. By
default (when using FileLogger), log files are created in the "logs"
directory relative to $CATALINA_HOME. If you wish, you can specify
a different directory with the "directory" attribute. Specify either a
relative (to $CATALINA_HOME) or absolute path to the desired
directory.-->
<Logger className="org.apache.catalina.logger.FileLogger"
directory="logs" prefix="localhost_log." suffix=".txt"
timestamp="true"/>
</Host>
</Engine>
</Service>
</Server>

View File

@@ -0,0 +1,143 @@
<?xml version='1.0'?>
<!DOCTYPE policy PUBLIC
"-//JBoss//DTD JBOSS Security Config 3.0//EN"
"http://www.jboss.org/j2ee/dtd/security_config.dtd">
<!-- The XML based JAAS login configuration read by the
org.jboss.security.auth.login.XMLLoginConfig mbean. Add
an application-policy element for each security domain.
The outline of the application-policy is:
<application-policy name="security-domain-name">
<authentication>
<login-module code="login.module1.class.name" flag="control_flag">
<module-option name = "option1-name">option1-value</module-option>
<module-option name = "option2-name">option2-value</module-option>
...
</login-module>
<login-module code="login.module2.class.name" flag="control_flag">
...
</login-module>
...
</authentication>
</application-policy>
$Revision$
-->
<policy>
<!-- Used by clients within the application server VM such as
mbeans and servlets that access EJBs.
-->
<application-policy name = "client-login">
<authentication>
<login-module code = "org.jboss.security.ClientLoginModule"
flag = "required">
</login-module>
</authentication>
</application-policy>
<!-- Security domain for JBossMQ -->
<application-policy name = "jbossmq">
<authentication>
<login-module code = "org.jboss.mq.sm.file.DynamicLoginModule"
flag = "required">
<module-option name = "unauthenticatedIdentity">guest</module-option>
<module-option name = "sm.objectname">jboss.mq:service=StateManager</module-option>
</login-module>
</authentication>
</application-policy>
<application-policy name = "SpringPoweredRealm">
<authentication>
<login-module code = "net.sf.acegisecurity.adapters.jboss.JbossAcegiLoginModule"
flag = "required">
<module-option name = "appContextLocation">acegisecurity.xml</module-option>
<module-option name = "key">my_password</module-option>
</login-module>
</authentication>
</application-policy>
<!-- Security domains for testing new jca framework -->
<application-policy name = "HsqlDbRealm">
<authentication>
<login-module code = "org.jboss.resource.security.ConfiguredIdentityLoginModule"
flag = "required">
<module-option name = "principal">sa</module-option>
<module-option name = "userName">sa</module-option>
<module-option name = "password"></module-option>
<module-option name = "managedConnectionFactoryName">jboss.jca:service=LocalTxCM,name=DefaultDS</module-option>
</login-module>
</authentication>
</application-policy>
<application-policy name = "FirebirdDBRealm">
<authentication>
<login-module code = "org.jboss.resource.security.ConfiguredIdentityLoginModule"
flag = "required">
<module-option name = "principal">sysdba</module-option>
<module-option name = "userName">sysdba</module-option>
<module-option name = "password">masterkey</module-option>
<module-option name = "managedConnectionFactoryName">jboss.jca:service=XaTxCM,name=FirebirdDS</module-option>
</login-module>
</authentication>
</application-policy>
<application-policy name = "JmsXARealm">
<authentication>
<login-module code = "org.jboss.resource.security.ConfiguredIdentityLoginModule"
flag = "required">
<module-option name = "principal">guest</module-option>
<module-option name = "userName">guest</module-option>
<module-option name = "password">guest</module-option>
<module-option name = "managedConnectionFactoryName">jboss.jca:service=TxCM,name=JmsXA</module-option>
</login-module>
</authentication>
</application-policy>
<!-- A template configuration for the jmx-console web application. This
defaults to the UsersRolesLoginModule the same as other and should be
changed to a stronger authentication mechanism as required.
-->
<application-policy name = "jmx-console">
<authentication>
<login-module code="org.jboss.security.auth.spi.UsersRolesLoginModule"
flag = "required" />
</authentication>
</application-policy>
<!-- A template configuration for the web-console web application. This
defaults to the UsersRolesLoginModule the same as other and should be
changed to a stronger authentication mechanism as required.
-->
<application-policy name = "web-console">
<authentication>
<login-module code="org.jboss.security.auth.spi.UsersRolesLoginModule"
flag = "required" />
</authentication>
</application-policy>
<!-- The default login configuration used by any security domain that
does not have a application-policy entry with a matching name
-->
<application-policy name = "other">
<!-- A simple server login module, which can be used when the number
of users is relatively small. It uses two properties files:
users.properties, which holds users (key) and their password (value).
roles.properties, which holds users (key) and a comma-separated list of
their roles (value).
The unauthenticatedIdentity property defines the name of the principal
that will be used when a null username and password are presented as is
the case for an unuathenticated web client or MDB. If you want to
allow such users to be authenticated add the property, e.g.,
unauthenticatedIdentity="nobody"
-->
<authentication>
<login-module code = "org.jboss.security.auth.spi.UsersRolesLoginModule"
flag = "required" />
</authentication>
</application-policy>
</policy>

View File

@@ -0,0 +1,87 @@
<?xml version="1.0"?>
<!DOCTYPE Configure PUBLIC "-//Mort Bay Consulting//DTD Configure 1.2//EN" "http://jetty.mortbay.org/configure_1_2.dtd">
<!-- $Id$ -->
<!-- =============================================================== -->
<!-- Configure the Jetty Server -->
<!-- =============================================================== -->
<Configure class="org.mortbay.jetty.Server">
<!-- =============================================================== -->
<!-- Configure the Request Listeners -->
<!-- =============================================================== -->
<!-- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -->
<!-- Add and configure a HTTP listener to port 8080 -->
<!-- The default port can be changed using: java -Djetty.port=80 -->
<!-- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -->
<Call name="addListener">
<Arg>
<New class="org.mortbay.http.SocketListener">
<Set name="Port"><SystemProperty name="jetty.port" default="8080"/></Set>
<Set name="MinThreads">5</Set>
<Set name="MaxThreads">50</Set>
<Set name="MaxIdleTimeMs">30000</Set>
<Set name="LowResourcePersistTimeMs">1000</Set>
<Set name="ConfidentialPort">8443</Set>
<Set name="IntegralPort">8443</Set>
<Set name="PoolName">main</Set>
</New>
</Arg>
</Call>
<Call name="instance" class="org.mortbay.util.Log">
<Call name="add">
<Arg>
<New class="org.mortbay.util.OutputStreamLogSink">
<Set name="filename"><SystemProperty name="jetty.home" default="."/>/logs/yyyy_mm_dd.jetty.log</Set>
<Set name="retainDays">90</Set>
<Set name="append">true</Set>
<Set name="logLabels">true</Set>
<Set name="logStackSize">true</Set>
<Set name="logStackTrace">false</Set>
<Set name="logOneLine">false</Set>
<Set name="logTimeZone">GMT</Set>
<Call name="start"/>
</New>
</Arg>
</Call>
</Call>
<!-- =============================================================== -->
<!-- Configure the Contexts -->
<!-- =============================================================== -->
<!-- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -->
<!-- Add a all web application within the webapps directory. -->
<!-- + No virtual host specified -->
<!-- + Look in the webapps directory relative to jetty.home or . -->
<!-- + Use the webdefault.xml resource for the defaults descriptor -->
<!-- + Upack the war file -->
<!-- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -->
<Set name="rootWebApp">root</Set>
<Call name="addWebApplications">
<Arg></Arg>
<Arg><SystemProperty name="jetty.home" default="."/>/webapps/</Arg>
<Arg><SystemProperty name="jetty.home" default="."/>/etc/webdefault.xml</Arg>
<Arg type="boolean">true</Arg>
</Call>
<!-- =============================================================== -->
<!-- Configure the Other Server Options -->
<!-- =============================================================== -->
<Set name="requestsPerGC">2000</Set>
<Set name="statsOn">false</Set>
<Call name="addRealm">
<Arg>
<New class="net.sf.acegisecurity.adapters.jetty.JettyAcegiUserRealm">
<Arg>Spring Powered Realm</Arg>
<Arg>my_password</Arg>
<Arg>/etc/acegisecurity.xml</Arg>
</New>
</Arg>
</Call>
</Configure>

View File

@@ -0,0 +1,4 @@
All of the JARs included in this lib directory were obtained from the
HttpUnit distribution archive. See http://httpunit.sourceforge.net.
$Id$

View File

@@ -0,0 +1,27 @@
# Ant properties for running the integration test.
# Values in this file will be overriden by any values with the same name
# in the user-created build.properties file.
# $Id$
name=acegi-security-integration-tests
tmp.dir=${basedir}/temporary
httpunit.lib.dir=${basedir}/lib
containers.dir=${basedir}/containers
config.dir=${basedir}/container-configs
lib.dir=${basedir}/../lib
dist.lib.dir=${basedir}/../dist
contacts.war=${basedir}/../samples/contacts/dist/contacts.war
acegisecurity.xml=../src/net/sf/acegisecurity/adapters/acegisecurity.xml
jalopy.xml=${basedir}/../jalopy.xml
src.dir=src
build.dir=classes
reports.dir=reports
test.includes=**/*TestSuite.class **/*Tests.class
test.excludes=**/Abstract*

View File

@@ -0,0 +1,24 @@
===============================================================================
ACEGI SECURITY SYSTEM FOR SPRING - INTEGRATION TESTS
===============================================================================
This directory allows execution of "in container" integration tests. To run
the tests, the original distribution files for various containers are required
to be placed into the containers directory. These are not included in CVS or
ZIP releases due to their large size.
To execute these tests:
1. The following files should be placed into the containers directory:
Jetty-4.2.18-all.zip (see http://mortbay.jetty.org)
jakarta-tomcat-5-0.19.zip (see http://jakarta.apache.org/tomcat)
jboss-3.2.3.zip (see http://www.jboss.org)
2. Shutdown any container or service bound to port 8080.
3. Run "ant tests" (you can safely ignore the console output).
4. Review the reports directory and confirm each container passed all tests.
$Id$

View File

@@ -0,0 +1,271 @@
/*
* The Acegi Security System for Spring is published under the terms
* of the Apache Software License.
*
* Visit http://acegisecurity.sourceforge.net for further details.
*/
package net.sf.acegisecurity.integrationtests.web;
import com.meterware.httpunit.GetMethodWebRequest;
import com.meterware.httpunit.WebConversation;
import com.meterware.httpunit.WebForm;
import com.meterware.httpunit.WebLink;
import com.meterware.httpunit.WebRequest;
import com.meterware.httpunit.WebResponse;
import junit.framework.TestCase;
import java.net.URL;
/**
* Tests the Contacts sample application and container integration from a HTTP
* user's perspective.
*
* <P>
* NB: Assumes a default container configuration concerning the usernames and
* passwords in <code>acegisecurity.xml</code>. Also assumes default
* configuration in terms of password and username case sensitivity.
* Importantly, the Contacts application is expected to be started "clean", in
* that all default contacts data is present, without any additional data.
* This means it is necessary to restart the Contacts application between
* successive test runs.
* </p>
*
* @author Ben Alex
* @version $Id$
*/
public class ContactsWarTests extends TestCase {
//~ Methods ================================================================
public final void setUp() throws Exception {
super.setUp();
}
public static void main(String[] args) {
junit.textui.TestRunner.run(ContactsWarTests.class);
}
public void testHelloPageAccessible() throws Exception {
WebConversation conversation = new WebConversation();
WebRequest request = new GetMethodWebRequest(
"http://localhost:8080/contacts");
WebResponse response = conversation.getResponse(request);
assertEquals("Contacts Security Demo", response.getTitle());
assertEquals(2, response.getLinks().length); // debug and manage links
assertTrue(response.getText().lastIndexOf("sample.contact.Contact@") != -1);
}
public void testLoginNameCaseSensitive() throws Exception {
WebConversation conversation = new WebConversation();
WebRequest request = new GetMethodWebRequest(
"http://localhost:8080/contacts");
WebResponse helloPage = conversation.getResponse(request);
WebLink debugLink = helloPage.getLinkWith("Debug");
WebResponse loginPage = debugLink.click();
assertEquals(1, loginPage.getForms()[0].getSubmitButtons().length);
WebForm loginForm = loginPage.getForms()[0];
loginPage = null;
loginForm.setParameter("j_username", "mArIsSA");
loginForm.setParameter("j_password", "koala");
WebResponse loginOutcome = conversation.getResponse(loginForm
.getRequest("submit"));
assertTrue(loginOutcome.getText().lastIndexOf("SUCCESS! Your container adapter appears to be properly configured!") != -1);
}
public void testLoginPasswordCaseSensitive() throws Exception {
WebConversation conversation = new WebConversation();
WebRequest request = new GetMethodWebRequest(
"http://localhost:8080/contacts");
WebResponse helloPage = conversation.getResponse(request);
WebLink debugLink = helloPage.getLinkWith("Debug");
WebResponse loginPage = debugLink.click();
assertEquals(1, loginPage.getForms()[0].getSubmitButtons().length);
WebForm loginForm = loginPage.getForms()[0];
loginPage = null;
loginForm.setParameter("j_username", "dianne");
loginForm.setParameter("j_password", "EmU");
WebResponse loginOutcome = conversation.getResponse(loginForm
.getRequest("submit"));
assertEquals("Login", loginOutcome.getTitle());
}
public void testLoginSuccess() throws Exception {
WebConversation conversation = new WebConversation();
WebRequest request = new GetMethodWebRequest(
"http://localhost:8080/contacts");
WebResponse helloPage = conversation.getResponse(request);
WebLink debugLink = helloPage.getLinkWith("Debug");
WebResponse loginPage = debugLink.click();
assertEquals(1, loginPage.getForms()[0].getSubmitButtons().length);
WebForm loginForm = loginPage.getForms()[0];
loginPage = null;
loginForm.setParameter("j_username", "marissa");
loginForm.setParameter("j_password", "koala");
WebResponse loginOutcome = conversation.getResponse(loginForm
.getRequest("submit"));
assertTrue(loginOutcome.getText().lastIndexOf("SUCCESS! Your container adapter appears to be properly configured!") != -1);
}
public void testLoginUnknownUsername() throws Exception {
WebConversation conversation = new WebConversation();
WebRequest request = new GetMethodWebRequest(
"http://localhost:8080/contacts");
WebResponse helloPage = conversation.getResponse(request);
WebLink debugLink = helloPage.getLinkWith("Debug");
WebResponse loginPage = debugLink.click();
assertEquals(1, loginPage.getForms()[0].getSubmitButtons().length);
WebForm loginForm = loginPage.getForms()[0];
loginPage = null;
loginForm.setParameter("j_username", "angella");
loginForm.setParameter("j_password", "echidna");
WebResponse loginOutcome = conversation.getResponse(loginForm
.getRequest("submit"));
assertEquals("Login", loginOutcome.getTitle());
}
public void testSessionAsMarissa() throws Exception {
WebConversation conversation = new WebConversation();
WebRequest request = new GetMethodWebRequest(
"http://localhost:8080/contacts");
WebResponse helloPage = conversation.getResponse(request);
WebLink manageLink = helloPage.getLinkWith("Manage");
WebResponse loginPage = manageLink.click();
manageLink = null;
assertEquals(1, loginPage.getForms()[0].getSubmitButtons().length);
WebForm loginForm = loginPage.getForms()[0];
loginPage = null;
loginForm.setParameter("j_username", "marissa");
loginForm.setParameter("j_password", "koala");
WebResponse loginOutcome = conversation.getResponse(loginForm
.getRequest("submit"));
assertEquals("Your Contacts", loginOutcome.getTitle());
assertTrue(loginOutcome.getText().lastIndexOf("marissa's Contacts") != -1);
assertEquals(4, loginOutcome.getTables()[0].getRowCount()); // 3 contacts + header
assertEquals(5, loginOutcome.getLinks().length); // 3 contacts + add + logoff
WebLink addLink = loginOutcome.getLinkWith("Add");
loginOutcome = null;
WebResponse addPage = addLink.click();
WebForm addForm = addPage.getForms()[0];
addPage = null;
addForm.setParameter("name", "");
addForm.setParameter("email", "");
WebResponse addOutcomeFail = conversation.getResponse(addForm
.getRequest("execute"));
assertEquals(new URL("http://localhost:8080/contacts/secure/add.htm"),
addOutcomeFail.getURL());
assertTrue(addOutcomeFail.getText().lastIndexOf("Please fix all errors!") != -1);
addOutcomeFail = null;
addForm.setParameter("name", "somebody");
addForm.setParameter("email", "them@somewhere.com");
WebResponse addOutcomeSuccess = conversation.getResponse(addForm
.getRequest("execute"));
assertEquals("Your Contacts", addOutcomeSuccess.getTitle());
assertTrue(addOutcomeSuccess.getText().lastIndexOf("marissa's Contacts") != -1);
assertEquals(5, addOutcomeSuccess.getTables()[0].getRowCount()); // 4 contacts + header
assertEquals(6, addOutcomeSuccess.getLinks().length); // 4 contacts + add + logoff
WebLink logout = addOutcomeSuccess.getLinkWith("Logoff");
addOutcomeSuccess = null;
WebResponse loggedOut = logout.click();
assertEquals("Contacts Security Demo", loggedOut.getTitle());
WebLink debugLink = loggedOut.getLinkWith("Debug");
loggedOut = null;
WebResponse loginAgainPage = debugLink.click();
assertEquals("Login", loginAgainPage.getTitle());
}
public void testSessionAsScott() throws Exception {
WebConversation conversation = new WebConversation();
WebRequest request = new GetMethodWebRequest(
"http://localhost:8080/contacts");
WebResponse helloPage = conversation.getResponse(request);
WebLink manageLink = helloPage.getLinkWith("Manage");
WebResponse loginPage = manageLink.click();
manageLink = null;
assertEquals(1, loginPage.getForms()[0].getSubmitButtons().length);
WebForm loginForm = loginPage.getForms()[0];
loginPage = null;
loginForm.setParameter("j_username", "scott");
loginForm.setParameter("j_password", "wombat");
WebResponse loginOutcome = conversation.getResponse(loginForm
.getRequest("submit"));
assertEquals("Your Contacts", loginOutcome.getTitle());
assertTrue(loginOutcome.getText().lastIndexOf("scott's Contacts") != -1);
assertEquals(3, loginOutcome.getTables()[0].getRowCount()); // 2 contacts + header
assertEquals(2, loginOutcome.getLinks().length); // add + logoff only
WebLink addLink = loginOutcome.getLinkWith("Add");
loginOutcome = null;
WebResponse addPage = addLink.click();
WebForm addForm = addPage.getForms()[0];
addPage = null;
addForm.setParameter("name", "somebody");
addForm.setParameter("email", "them@somewhere.com");
WebResponse addOutcomeSuccess = conversation.getResponse(addForm
.getRequest("execute"));
assertEquals("Your Contacts", addOutcomeSuccess.getTitle());
assertTrue(addOutcomeSuccess.getText().lastIndexOf("scott's Contacts") != -1);
assertEquals(4, addOutcomeSuccess.getTables()[0].getRowCount()); // 3 contacts + header
assertEquals(2, addOutcomeSuccess.getLinks().length); // add + logoff only
WebLink logout = addOutcomeSuccess.getLinkWith("Logoff");
addOutcomeSuccess = null;
WebResponse loggedOut = logout.click();
assertEquals("Contacts Security Demo", loggedOut.getTitle());
WebLink debugLink = loggedOut.getLinkWith("Debug");
loggedOut = null;
WebResponse loginAgainPage = debugLink.click();
assertEquals("Login", loginAgainPage.getTitle());
}
}