Showing posts with label Spring. Show all posts
Showing posts with label Spring. Show all posts

Wednesday, May 7, 2008

How to present the version number on a web front end with spring and maven

Blink It Digg! Dzone

This bog will describe how to present a application version number in
the pom.xml on a web front end by using spring and maven. Maven
generates by default a pom.properties file in the META-INF folder when
generating a war. This file holds the following fields; version,
groupId, artifactId

The exact location from your context root is;

META-INF/maven/<groupId>/<artifactId>/pom.properties


by specifying the following bean in your spring config; (REPLACE
<groupId> and <artifactId> with what you have defined in your pom.xml)

<bean id="messageSource"
class="org.springframework.context.support.ReloadableResourceBundleMessageSource"
>
<property name="basenames">
<list>
<value>META-INF/maven/<groupId>/<artifactId>/pom</value>
</list>
</property>
</bean>


Now the properties in this file can be used in your font-end by using
the standard spring tags for example to print the version number in a
jsp file use the following line;

<b>Version:</b> <spring:message code="version"/>


REMARK don't forget to add the spring tag definition to your jsp file;

<%@ taglib prefix="spring" uri="http://www.springframework.org/tags" %>

Monday, August 13, 2007

Remember me with ageci security

Blink It Digg! Dzone

Remembering returning vistors logon is nice functionality for your website. Ageci security is nice tool what offers this functionality with just what configuration. This topic will help you configuring the remember me authentification based on a form login with Java Authentication and Authorization Service (JAAS).

Remember me functionality is one of the more insucure features of a website. Remember me functionality works on a client side cookie. A cookie can be tampered with or stolen by an hacker, that is why you should be carefull implementing a remember me service.

Wednesday, August 1, 2007

Multi threaded JMS with Lingo and Jencks

Blink It Digg! Dzone

In the previous article about Lingo JMS with Lingo we took care of a simple Lingo implementation. In that article we discussed that Lingo does not support out of the box a multi threaded server side. This article will discuss the steps to take to get your Lingo implementation to the next level.

To get the server side to process server calls on multiple threads we going to use Jencks. Jencks is a implementation of the J2EE Connector Architecture (JCA). For now we are just going to implement a simple multi threaded solution without transactions.

The client side is exactly the same as discused in JMS with Lingo, for more info about how to setup the Lingo client site I refer to this article.

The server side is also the same as discused in JMS with Lingo, but additinal to this configuration for Jecks needs some configuration to take care of multi threading part.


<!-- JCA container -->
<bean id="jencks" class="org.jencks.JCAContainer">

<!-- lets use the default configuration of work manager and transaction manager-->
<property name="bootstrapContext">
<bean class="org.jencks.factory.BootstrapContextFactoryBean">
<property name="threadPoolSize" value="25" />
</bean>
</property>


<!-- the JCA Resource Adapter -->
<property name="resourceAdapter">
<bean id="activeMQResourceAdapter"
class="org.apache.activemq.ra.ActiveMQResourceAdapter">
<property name="serverUrl" value="tcp://localhost:61626" />
</bean>
</property>
</bean>

<!-- an inbound message connector using a stateless, thread safe MessageListener -->
<bean id="inboundMessageA" class="org.jencks.JCAConnector">

<property name="jcaContainer" ref="jencks" />

<!-- subscription details -->
<property name="activationSpec">
<bean class="org.apache.activemq.ra.ActiveMQActivationSpec">
<property name="destination"
value="org.isthisjava.service.jca.ExampleService" />
<property name="destinationType" value="javax.jms.Queue" />
</bean>
</property>

<property name="ref" value="exampleService" />
</bean>


When you want more details for the multi threaded client and server, the complete source code is added at the end of this page. If you want to see it in action just drop the server end client binaries into tomcat. and point your browser to http://locahost:8080/somepathtothemultithreadedclient

TODO add source and binaries

Sunday, July 29, 2007

JMS with Lingo

Blink It Digg! Dzone

Lingo is one of those little projects what make life a lot easier for a java developer. According to the Lingo people Lingo is a lightweight POJO based remoting and messaging library based on Spring's Remoting which extends it to support JMS. Lingo can support a wide range of message exchange patterns including both synchronous and asynchronous message exchange.

I came across Lingo when I was searching for a really simple JMS solution. Ofcourse I looked into Spring but I didn't like what they offered. In my opinion spring JMS (Message Driven POJO) was still to low level for me. I was searching for a real POJO based solution what handles all the messaging for me, and that is just the thing Lingo does.

This article is focused around how to setup Lingo correctly in your environment. At the bottom you find a link to the source code with a sample client implementation, and a sample server implementation. These project are both web based, they where tested in a default Tomcat 5.5.23, and a default Active MQ 4.1.1. Active MQ is used as a JMS message broker.

The client consist out of two pages, the first page will initiate the call to the server, the second page will present the result to the user. A sample of the client side spring config is represented below. For Lingo client side 3 beans are defined, the actual service, the JMS broker, and the queue where to send the message to. The last two must also be present in the server side spring config.


<!-- client side proxy-->
<bean id="exampleService" class="org.logicblaze.lingo.jms.JmsProxyFactoryBean">

<property name="serviceInterface" value="org.isthisjava.service.ExampleService"/>
<property name="connectionFactory" ref="jmsFactory"/>
<property name="destination" ref="exampleDestination"/>
</bean>

<!-- JMS ConnectionFactory to use -->
<bean id="jmsFactory" class="org.apache.activemq.ActiveMQConnectionFactory">
<property name="brokerURL" value="tcp://localhost:61616"/>
</bean>

<bean id="exampleDestination" class="org.apache.activemq.command.ActiveMQQueue">
<constructor-arg index="0" value="org.isthisjava.service.ExampleService"/>
</bean>


For the Lingo server side consist out of 4 beans, the actual POJO implementation of the service, a setup for the POJO so that it will listen to incomming messages, and the JMS broker and the queue definition. The last two are also in the client configuration. Take in account that this configuration is a single threaded solution. A single threaded solution is okee for the client side, but the server side should be multi threaded. How to make your server side multi threaded will be discussed in a later article.


<!-- the server side -->
<bean class="org.logicblaze.lingo.jms.JmsServiceExporter">
<property name="service" ref="serverImpl"/>
<property name="serviceInterface" value="org.isthisjava.service.ExampleService"/>
<property name="connectionFactory" ref="jmsFactory"/>
<property name="destination" ref="exampleDestination"/>
</bean>

<!-- the actual implementation of the service - which is only made public for testing purposes -->
<bean id="exampleServiceImpl" class="org.isthisjava.service.ExampleServiceImpl" singleton="true"/>


In the source code added to this article you will find the ExampleService and a simple implementation of this service. For more details please look into the source code.

If you just want to see a demo please install Active MQ and drop the two wars (see binary) in your Tomcat, and navigate to http://localhost:8080/jmswithlingoclient

jmswithlingoclient-src-1.0.zip
jmswithlingoclient-bin-1.0.zip
jmswithlingoserver-src-1.0.zip
jmswithlingoserver-bin-1.0.zip

Wednesday, July 25, 2007

CAS with ageci security

Blink It Digg! Dzone

At my latest project I got the opportunity to use CAS server in combination with acegi security. With this setup it is possible to have a real single sign-on authentication over multiple contexts and servers.

On the acegi security site and the CAS site I could not find a tutorial to get this setup up and running correctly. It took me several days to get a hello world setup up and running. The biggest problem came across was outdated ageci security documentation. It seems that they did some refactoring in there code base! Additional I had some problem to get tomcat (https) configured correctly. This article will give you a guide on how to get this hello world setup up and running from scratch.

My setup is based on tomcat I used tomcat version 5.5.23 as my servlet engine. CAS needs to run on https, for https you need to sign your JDK by generating a certificate and add this to the jks keychain. WARNING generating the certificate use ‘localhost ’ as your name or common name, otherwise tomcat will not except this certificate.


$JAVA_HOME\bin\keytool -delete -alias tomcat -keypass changeit
$JAVA_HOME\bin\keytool -genkey -alias tomcat -keypass changeit -keyalg RSA
$JAVA_HOME\bin\keytool -export -alias tomcat -keypass changeit -file server.crt
$JAVA_HOME\bin\keytool -import -file server.crt -keypass changeit -keystore %JAVA_HOME\jre\lib\security\cacerts
$JAVA_HOME\bin\keytool -import -file server.crt -keypass changeit

For tomcat to accept https request the next few lines should be added to the server.xml. The .keystore file can be found in your home folder.

<Connector port="8443" maxHttpHeaderSize="8192"
maxThreads="150" minSpareThreads="25" maxSpareThreads="75"
enableLookups="false" disableUploadTimeout="true"
acceptCount="100" scheme="https" secure="true"
clientAuth="false" sslProtocol="TLS" keystoreFile="/path/to/.keystore"
keystorePass="changeit"/>

To get CAS going download the latest 3.x release, I used 3.1 and drop the cas.war in tomcat. For a simple hello world application CAS doesn't need any more configuration. CAS will aunthenticate all user who have the same username as password, I will come back to this later on

Ageci security was for me alot more difficult to setup correctly. The article will only walk you through the basics, for more details I refer to the source code.

<bean id="inMemoryDaoImpl" class="org.acegisecurity.userdetails.memory.InMemoryDaoImpl">
<property name="userMap">
<value>
marissa=marissa,ROLE_USER,ROLE_SUPERVISOR
dianne=dianne,ROLE_USER
scott=scott,ROLE_USER
peter=peter,ROLE_USER
</value>
</property>
</bean>

<bean id="casAuthenticationProvider" class="org.acegisecurity.providers.cas.CasAuthenticationProvider">
<property name="casAuthoritiesPopulator"><ref local="casAuthoritiesPopulator"/></property>
<property name="casProxyDecider"><ref local="casProxyDecider"/></property>
<property name="ticketValidator"><ref local="casProxyTicketValidator"/></property>
<property name="statelessTicketCache"><ref local="statelessTicketCache"/></property>
<property name="key"><value>my_password_for_this_auth_provider_only</value></property>
</bean>

Ageci is set up around the inMemoryDaoImpl, four users are defined marissa, dianne, scott, and peter. This DAO is used to get the credentials for the users who are authenticated by CAS, CAS can only check if a user is authenticated. The CasAuthenticationProvider has a special field 'key' what should be set to some special phrase. This phrase is used with-in CAS to distinguish the different client applications. This is necessary for applications what need extra security for instance for some applications CAS needs to re-check the credentials of the user to match the security requirements.

To see all the CAS magic in action for you self, you can download the source or binary with the following links
caswithageci-bin-1.0.zip
caswithageci-src-1.0.zip

The release notes can be found here

Additional info about this article
I see a casfailed.jsp page