tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Mark Thomas <ma...@apache.org>
Subject Re: Realm Tag in webappnamecontext.xml
Date Fri, 02 Jun 2006 23:10:02 GMT
Marc Farrow wrote:
>  <auth-contraint/>

And there is the problem. An empty <auth-constraint> allows
unauthenticated access as per SRV.12.8.1

An empty <auth-constraint> is not the same as an <auth-constraint>
that specifies no roles and therefore denies access to all as per
SRV.12.8.1.


Mark

---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
For additional commands, e-mail: users-help@tomcat.apache.org


Mime
View raw message