Book Image

JBoss AS 5 Development

Book Image

JBoss AS 5 Development

Overview of this book

JBoss AS is the most used Java application server on the market meeting high standards of reliability, efficiency, and robustness and is used to build powerful and secure Java EE applications. It supports the most important areas of Java Enterprise programming including EJB 3.0, dependency injection, web services, the security framework, and more. Getting started with JBoss application server development can be challenging; however, with the right approach and guidance, you can easily master it and this book promises that. Written in an easy-to-read style, this book will take you from the basics of JBoss ASósuch as installing core components and plug-insóto the skills that will make you a JBoss developer to be reckoned with, covering advanced topics such as developing applications with JBoss Messaging service, JBoss web services, clustered applications, and more. You will learn the necessary steps to install a suitable environment for developing enterprise applications on JBoss AS. Then, your journey will continue through the heart of the application server, explaining how to customize each service for optimal usage. You will learn how to design Enterprise applications using Eclipse and JBoss plug-ins. You will then learn how to enable distributed communication using JMS. Storing and retrieving objects will be made easier using Hibernate. The core section of the book will take you into the programming arena with tested, real-world examples. The example programs have been carefully crafted to be easy to understand and useful as starting points for your applications. This book will kick-start your productivity and help you to master JBoss AS development. The author's experience with JBoss enables him to share insights on JBoss AS development, in a clear and friendly way. By the end of the book, you will have the confidence to apply all the newest programming techniques to your JBoss applications.
Table of Contents (20 chapters)
JBoss AS 5 Development
Credits
About the Author
About the Reviewers
Preface
8
Developing Applications with JBoss and Hibernate
Index

Securing the AppStore application


We initially designed our AppStore application as a single node Enterprise. Later in Chapter 12, we upgraded it as a clustered application. The only thing missing now is an adequate security infrastructure for it.

Before planning security, you have to analyze what exactly needs to be secured. For example, the AppStore application was made up of a JSF frontend layer and an EJB middle tier that consisted of a session bean and two entity beans.

In such a scenario, if you don't plan to directly expose the EJB layer to your clients, then it's usually enough to apply security only on the HTTP layer, which is the only point reachable by untrusted entities. On the other hand, if chances are that your middle tier will be available straight to your clients, then you have to apply security at this level too. Let's start by creating an access control list to the AppStore web layer; later we will analyze how to secure EJB access.

HTTP role authentication

In the last chapter...