426 Spring Security
426 Spring Security
426 Spring Security
HTTP
Server
Success (HTTP 200) Result Failure
Request
GET Service Intercept-URI Rules
POST
PUT
JSESSIONID Resource URI
DELETE (Cookie) Anonymous
HTTP 500
Extracted
Client-Principal Roles or Yes
Permit All
No
Session Session
No Present Yes Memory AppServer
Matching Role Yes Request
j_username
POST j_spring_security_check Authenticate RestApplicationAuth OERealmUserDetails
j_password
JSESSIONID [new]
HTTP 403
Session Created
JSESSIONID [blank] Memory Client-Principal
OERealmUserDetailsImpl
ValidateUser
-1 <username>
Delete Session
/static/auth/ >0
GET JSESSIONID j_spring_security_logout
Find
(Cookie) Session realmClass at realmURL
GetAttribute (AppServerDC://<host>:<port>/oerealm)
Logout ATTR_ENABLED
GetAttribute
true ATTR_EXPIRED
method public logical RemoveAttribute
Role List
ValidatePassword
false <password>
true