Return-Path: Delivered-To: apmail-struts-user-archive@www.apache.org Received: (qmail 43973 invoked from network); 3 Jun 2004 12:31:49 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (209.237.227.199) by minotaur-2.apache.org with SMTP; 3 Jun 2004 12:31:49 -0000 Received: (qmail 86988 invoked by uid 500); 3 Jun 2004 12:31:17 -0000 Delivered-To: apmail-struts-user-archive@struts.apache.org Received: (qmail 86796 invoked by uid 500); 3 Jun 2004 12:31:15 -0000 Mailing-List: contact user-help@struts.apache.org; run by ezmlm Precedence: bulk List-Unsubscribe: List-Subscribe: List-Help: List-Post: List-Id: "Struts Users Mailing List" Reply-To: "Struts Users Mailing List" Delivered-To: mailing list user@struts.apache.org Received: (qmail 86660 invoked by uid 99); 3 Jun 2004 12:31:14 -0000 Received: from [203.197.24.225] (HELO InMumG01.tcs.com) (203.197.24.225) by apache.org (qpsmtpd/0.27.1) with ESMTP; Thu, 03 Jun 2004 05:31:14 -0700 Received: from InMumG01.tcs.com ([172.17.9.35]) by InMumG01.tcs.com (Lotus Domino Release 6.0.3) with SMTP id 2004060318010157-36621 ; Thu, 3 Jun 2004 18:01:01 +0530 In-Reply-To: <000001c44953$19f953a0$a230010a@infotech.com> To: "Struts Users Mailing List" Cc: "'Struts Users Mailing List'" Subject: Re: Servlet filter MIME-Version: 1.0 X-Mailer: Lotus Notes Release 6.5 September 26, 2003 From: brati.sankarghosh@tcs.com Message-ID: Date: Thu, 3 Jun 2004 17:59:13 +0530 X-MIMETrack: Serialize by Router on InKolM01/TCS(Release 6.0.3|September 18, 2003) at 06/03/2004 18:01:05, Serialize complete at 06/03/2004 18:01:05, Itemize by SMTP Server on InMumG01/TCS(Release 6.0.3|September 26, 2003) at 06/03/2004 06:01:01 PM, Serialize by Router on InMumG01/TCS(Release 6.0.3|September 26, 2003) at 06/03/2004 06:01:06 PM, Serialize complete at 06/03/2004 06:01:06 PM Content-Type: multipart/mixed; boundary="----=_NextPartTM-000-73e75a24-130e-4fdd-a399-058b955144cb" X-Virus-Checked: Checked X-Spam-Rating: minotaur-2.apache.org 1.6.2 0/1000/N ------=_NextPartTM-000-73e75a24-130e-4fdd-a399-058b955144cb Content-Type: multipart/alternative; boundary="=_alternative 00451E6C65256EA8_=" --=_alternative 00451E6C65256EA8_= Content-Type: text/plain; charset="US-ASCII" Shilpa, We are doing just that. A filter comes into effect before the control goes to the servlet. So if you can stop the user at the filter level you are actually saving some processing. We are checking for the presence of session in the filter. Brati Sankar Ghosh Tata Consultancy Services Mailto: brati.sankarghosh@tcs.com Website: http://www.tcs.com "Shilpa Vaidya" 06/03/2004 03:41 PM Please respond to "Struts Users Mailing List" To "'Struts Users Mailing List'" cc Subject Servlet filter hey all, Preventing users from accesing action. I am writing a web app to manage administrators and profiles. Administrators may access to the web app based on the profiles they have. The profiles, determine which pages the administrator might access. The profiles, and authorizations, might change online during work, so I need to check authorization to access a page (Action) on each access.If I understand correct, then, the actionServlet, first process the form bean, and then the action.. But, if the user is not authorized to access a specific page (Action), I need to forward him to an UnAuthorized error page, before thr formAction bean is filled. I would like to use a servlet filter. This filter checks the users rights and instanciates a HttpServletRequest-Wrapper.But am not sure how - .Can anyone help.Till then me trying to study the ServletFilter examples here n there. Shilpa -- "This e-mail message may contain confidential, proprietary or legally privileged information. It should not be used by anyone who is not the original intended recipient. If you have erroneously received this message, please delete it immediately and notify the sender. The recipient acknowledges that ICICI Bank or its subsidiaries and associated companies, (collectively "ICICI Group"), are unable to exercise control or ensure or guarantee the integrity of/over the contents of the information contained in e-mail transmissions and further acknowledges that any views expressed in this message are those of the individual sender and no binding nature of the message shall be implied or assumed unless the sender does so expressly with due authority of ICICI Group.Before opening any attachments please check them for viruses and defects." ForwardSourceID:NT0000A91E --=_alternative 00451E6C65256EA8_= Content-Type: text/html; charset="US-ASCII"
Shilpa,
We are doing just that. A filter comes into effect before the control goes to the servlet. So if you can stop the user at the filter level you are actually saving some processing. We are checking for the presence of session in the filter.

Brati Sankar Ghosh
Tata Consultancy Services
Mailto: brati.sankarghosh@tcs.com
Website: http://www.tcs.com



"Shilpa Vaidya" <shilpa.vaidya@icici-infotech.com>

06/03/2004 03:41 PM
Please respond to
"Struts Users Mailing List" <user@struts.apache.org>

To
"'Struts Users Mailing List'" <user@struts.apache.org>
cc
Subject
Servlet filter





hey all,
Preventing users from accesing action. I am writing a web app to manage
administrators and profiles.
Administrators may access to the web app based on the profiles they have.
The profiles, determine which pages the administrator might access. The
profiles, and authorizations, might change online during work, so I need to
check authorization to access a page (Action) on each access.If I understand
correct, then, the actionServlet, first process the form bean, and then the
action..
But, if the user is not authorized to access a specific page (Action), I
need to forward him to an UnAuthorized error page, before thr formAction
bean is filled.
I would like to use a servlet filter. This filter checks the users rights
and instanciates a HttpServletRequest-Wrapper.But am not sure how - .Can
anyone help.Till then me trying to study the ServletFilter examples here n
there.
Shilpa





--


"This e-mail message may contain confidential, proprietary or legally privileged information. It
should not be used by anyone who is not the original intended recipient. If you have erroneously
received this message, please delete it immediately and notify the sender. The recipient
acknowledges that ICICI Bank or its subsidiaries and associated companies,  (collectively "ICICI
Group"), are unable to exercise control or ensure or guarantee the integrity of/over the contents of the information contained in e-mail transmissions and further acknowledges that any views
expressed in this message are those of the individual sender and no binding nature of the message shall be implied or assumed unless the sender does so expressly with due authority of ICICI Group.Before opening any attachments please check them for viruses and defects."



ForwardSourceID:NT0000A91E    
--=_alternative 00451E6C65256EA8_=-- ------=_NextPartTM-000-73e75a24-130e-4fdd-a399-058b955144cb Content-Transfer-Encoding: 7bit Content-Type: text/plain; name="InterScan_Disclaimer.txt" Content-Disposition: attachment; filename="InterScan_Disclaimer.txt" DISCLAIMER: The information contained in this message is intended only and solely for the addressed individual or entity indicated in this message and for the exclusive use of the said addressed individual or entity indicated in this message (or responsible for delivery of the message to such person) and may contain legally privileged and confidential information belonging to Tata Consultancy Services. It must not be printed, read, copied, disclosed, forwarded, distributed or used (in whatsoever manner) by any person other than the addressee. Unauthorized use, disclosure or copying is strictly prohibited and may constitute unlawful act and can possibly attract legal action, civil and/or criminal. The contents of this message need not necessarily reflect or endorse the views of Tata Consultancy Services on any subject matter. Any action taken or omitted to be taken based on this message is entirely at your risk and neither the originator of this message nor Tata Consultancy Services takes any responsibility or liability towards the same. Opinions, conclusions and any other information contained in this message that do not relate to the official business of Tata Consultancy Services shall be understood as neither given nor endorsed by Tata Consultancy Services or any affiliate of Tata Consultancy Services. If you have received this message in error, you should destroy this message and may please notify the sender by e-mail. Thank you. ------=_NextPartTM-000-73e75a24-130e-4fdd-a399-058b955144cb Content-Type: text/plain; charset=us-ascii --------------------------------------------------------------------- To unsubscribe, e-mail: user-unsubscribe@struts.apache.org For additional commands, e-mail: user-help@struts.apache.org ------=_NextPartTM-000-73e75a24-130e-4fdd-a399-058b955144cb--