Any library for authentication in a java web-app?

2019-08-08 22:45发布

Hi I am look for a proven java security web-library which is a bit more low-level and therefore less intrusive than the well known frameworks spring-security and apache shiro.

Just something which has best-practive utility-apis for example to encode a remember-me cookie or for dighest authentication, accessing ldap. All the sutff which is so useful in the above frameworks but without needing to follow the frameworks filters and indriections an application-context or yet another ini file etc.

3条回答
Summer. ? 凉城
2楼-- · 2019-08-08 23:19

Well, you can always use the HttpServletRequest.login() method or j_security_check and implement an auth manager beneath it for your particular server, that's pretty much the default & low level standard thing... Your only real other choice is, as you mentioned, security frameworks.

查看更多
乱世女痞
3楼-- · 2019-08-08 23:19

If you don't want to use either of one, use container-managed security which both Tomcat and Jetty provide.

查看更多
别忘想泡老子
4楼-- · 2019-08-08 23:33

Have a look at the Apache Shiro project it does a lot more then the standard libraries, and makes it really easy.

查看更多
登录 后发表回答