Hi,

I'd like to set 2 different security contraints : /admin would be accessible with admin roles and the rest of my application with user roles. Only one security-constraint directive is allowed
How can i manage that ?

Rgards,

Phil

<security-constraint>
 <web-resource-collection>
   <web-resource-name>Entire Application</web-resource-name>
   <url-pattern>/*</url-pattern>
 </web-resource-collection>
 <auth-constraint>
     <role-name>user</role-name>
 </auth-constraint>
</security-constraint>

<security-constraint>
 <web-resource-collection>
   <web-resource-name>Admin</web-resource-name>
   <url-pattern>/admi*</url-pattern>
 </web-resource-collection>
 <auth-constraint>
     <role-name>admin</role-name>
 </auth-constraint>
</security-constraint>

<login-config>
 <auth-method>BASIC</auth-method>
 <realm-name>foo</realm-name>
</login-config>


---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to