Authentication and Authorization Stores in Payara Platform
Originally published on 07 Jul 2020
Last updated on 07 Jul 2020
Securing your application is a very important aspect of development. You not only need to make sure that the application has the intended functionality but also that this functionality can only be executed by the appropriate people. It is critical to ensure that updates to data are restricted to the correct people, and that end users only see data they are allowed to see. And in case of sensitive data, this is even more important.
The definition and configuration of these processes have become easier with the introduction of the Security API in Java EE 8 which is available in Payara Platform 5.
This guide describes concepts such as:
- HTTP Authentication Mechanism and Identity Store
- Groups vs. Role
- OAuth2 and OpenIdConnect
- Combining the Payara Realms with the Security API
- Detailed examples for how to use in the Payara Platform
Payara Platform has a multitude of possibilities to secure your application. We will introduce the concepts of the Security API and show detailed examples on how you can use it to secure the application using a hashed password stored in the database and using the Google OpenIdConnect functionality.
We will also discuss the option to define multiple IdentityStores to retrieves authorization information from multiple sources and using multiple stores for authentication which include creating a custom Identity Store handler for the veto concept.
And finally, we will describe how you can combine the Payara Realms with the Security API to
have even more possibilities.
Related Posts
The Payara Monthly Catch - October 2024
Published on 30 Oct 2024
by Chiara Civardi
0 Comments
Celebrating 25 Years of the CVE Program
Published on 22 Oct 2024
by Chiara Civardi
0 Comments
The Common Vulnerabilities and Exposures (CVE®) Program is celebrating its 25th anniversary today! This marks a major milestone in global cybersecurity. Since 1999, the CVE Program has been critical in helping organizations identify, manage and ...