%--
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
--%>
<%@ page import="java.net.URLEncoder" %>
<%@ page import="java.security.Principal" %>
<%@ page import="java.util.Enumeration" %>
<%@ page import="org.apache.catalina.TomcatPrincipal" %>
<%
if (request.getParameter("logoff") != null) {
session.invalidate();
response.sendRedirect("index.jsp");
return;
}
%>
Protected Page for Examples
You are logged in as remote user
<%= util.HTMLFilter.filter(request.getRemoteUser()) %>
in session <%= session.getId() %>
<%
if (request.getUserPrincipal() != null) {
%>
Your user principal name is
<%= util.HTMLFilter.filter(request.getUserPrincipal().getName()) %>
<%
} else {
%>
No user principal could be identified.
<%
}
%>
<%
String role = request.getParameter("role");
if (role == null)
role = "";
if (role.length() > 0) {
if (request.isUserInRole(role)) {
%>
You have been granted role
<%= util.HTMLFilter.filter(role) %>
<%
} else {
%>
You have not been granted role
<%= util.HTMLFilter.filter(role) %>
<%
}
}
%>
To check whether your user name has been granted a particular role,
enter it here:
<%
Principal p = request.getUserPrincipal();
if (!(p instanceof TomcatPrincipal)) {
%>
The principal does not support attributes.
<%
} else {
TomcatPrincipal principal = (TomcatPrincipal) p;
%>
The principal contains the following attributes:
Name | Value | Type |
<%
Enumeration names = principal.getAttributeNames();
while (names.hasMoreElements()) {
String name = names.nextElement();
Object value = principal.getAttribute(name);
String type = value != null ? value.getClass().getName() : "unknown";
if (value instanceof Object[]) {
Object[] values = (Object[]) value;
value = "";
for (int i = 0; i < values.length; i++) {
value += values[i] + "
";
}
if (values.length > 0) {
type = values[0].getClass().getName() + "[]";
} else {
type = "unknown";
}
}
type = type.replaceFirst("^java\\.lang\\.", "");
%>
<%= util.HTMLFilter.filter(name) %> |
<%= util.HTMLFilter.filter(String.valueOf(value)) %> |
<%= util.HTMLFilter.filter(type) %> |
<%
}
%>
<%
}
%>
<%
// Count the existing attributes
int sessionAttributeCount = 0;
Enumeration names = session.getAttributeNames();
while (names.hasMoreElements()) {
names.nextElement();
sessionAttributeCount++;
}
String dataName = request.getParameter("dataName");
String dataValue = request.getParameter("dataValue");
if (dataName != null) {
if (dataValue == null) {
session.removeAttribute(dataName);
sessionAttributeCount--;
} else if (sessionAttributeCount < 10) {
session.setAttribute(dataName, dataValue);
sessionAttributeCount++;
} else {
%>
Session attribute [<%= util.HTMLFilter.filter(dataName) %>] not added as there are already 10 attributes in the
session. Delete an attribute before adding another.
<%
}
}
if (sessionAttributeCount < 10) {
%>
To add some data to the authenticated session, enter it here:
<%
} else {
%>
You may not add more than 10 attributes to this session.
<%
}
%>
The authenticated session contains the following attributes:
Name | Value |
<%
names = session.getAttributeNames();
while (names.hasMoreElements()) {
String name = names.nextElement();
String value = session.getAttribute(name).toString();
%>
<%= util.HTMLFilter.filter(name) %> |
<%= util.HTMLFilter.filter(value) %> |
delete |
<%
}
%>
If you have configured this application for form-based authentication, you can
log off by clicking
here.
This should cause you to be returned to the login page after the redirect
that is performed.