security-constraint:允许一致的用户访问注册页面

时间:2016-07-12 08:04:03

标签: java authentication servlets

我在web.xml

中有这样的配置
<security-constraint>
    <display-name>Constraint-0</display-name>
    <web-resource-collection>
        <web-resource-name>Constraint-0</web-resource-name>
        <url-pattern>/books</url-pattern>
    </web-resource-collection>
    <auth-constraint>
        <role-name>Buyer</role-name>
    </auth-constraint>
    <user-data-constraint>
        <transport-guarantee>NONE</transport-guarantee>
    </user-data-constraint>
</security-constraint>

<security-constraint>
    <display-name>Constraint-1</display-name>
    <web-resource-collection>
        <web-resource-name>Constraint-1</web-resource-name>
        <url-pattern>/*</url-pattern>
    </web-resource-collection>
    <auth-constraint>
        <role-name>Seller</role-name>
    </auth-constraint>
    <user-data-constraint>
        <transport-guarantee>NONE</transport-guarantee>
    </user-data-constraint>
</security-constraint>

<login-config>
    <auth-method>FORM</auth-method>
    <form-login-config>
        <form-login-page>/login.jsp</form-login-page>
        <form-error-page>/failedlogin.jsp</form-error-page>
    </form-login-config>
</login-config>

<security-role>
    <role-name>Buyer</role-name>
</security-role>

<security-role>
    <role-name>Seller</role-name>
</security-role>

我想允许用户未经授权访问registration.jsp页面。

问题:为了让它发生,我应该添加到我的网页描述符中?

0 个答案:

没有答案