WebSphere Portal Server - using portlet filters for additional access control

This is Interesting: Free IT Magazines  
Home > Archive > WebSphere Portal Server > April 2005 > using portlet filters for additional access control





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author using portlet filters for additional access control

2005-04-06, 2:56 am

Hi,

My portal have to support normal (user/pass) authentication supported by WPS and more secure authentication method supported some external authentication service.
Only a few portlets are available to users that are
authenticated by user/pass-method and the rest are available to users that are authenticated by the external
service.

So I'm planning to use portlet filter to perform additional access control to few extra secure portlets in our portal.
My idea is to build a filter in front of these secure portlets that allows access to them only if user has authenticated with some external authentication service.
Authentication is verified by secure token (generated by the authentication service) in request header.
If user has not authenticated with external service filter should return a link (in the portlets view) to the authentication service.
If user chooses to authenticate with user/pass-method provided by portal he/she sees normally all the portlets that are not filtered by the filter.

For the authentication service I also need to build a TAI module for WAS to automatically authenticat/trust users authenticated in the external service.

Can you see any no-can-do in here, are there other options or is this the way to go ?

Regards,
jari
Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com