In my current web application I am trying to get rid of web.xml and I have not been able to properly setup the security constraint that forces all requests to the application to use HTTPS.
<security-constraint>
<web-resource-collection>
<web-resource-name>all</web-resource-name>
<url-pattern>/*</url-pattern>
</web-resource-collection>
<user-data-constraint>
<transport-guarantee>CONFIDENTIAL</transport-guarantee>
</user-data-constraint>
</security-constraint>
How can I turn the above web.xml configuration snippet in servlet 3.x configuration code that does the same thing?
UPDATE
I want the constraint to apply to every servlet, filter, and static resource in application, the examples I have seen online so far show to attach a security constraint to a servlet, but I want the security constraint attached to the web app. In the xml snippet above you see that it does not reference any specific servlet
I was able to do this for a project by configuring the glassfish domain security:
That covers your glassfish config, here is your web.xml:
I believe you are looking for the
@ServletSecurity
annotationOr with
ServletRegistration
in aServletContainerInitializer
(or anywhere you have access to aServletContext
)