clijava: passing user name
Posted in 2000
The poster wanted the Apache-authenticated web user name (from htpasswd) passed into his cjac.cnf command line so the Client/Java app could rsh to a Unix box as that user. He assumed $(FGL_AUTHUSER) wasn't usable; Ralf explained it is in fact set by the servlet to the Apache-authenticated user. It stayed empty because only the start HTML page was protected, not the servlet itself (/servlets/cjac). Andrej suggested also mapping it via cjac.app.*.env."REMOTEUSER", and, since /servlets/cjac is an alias rather than a real file, using an Apache <Location /servlets/cjac> block instead of <Files cjac> for the authentication. No confirmation from the poster that this worked is recorded.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Security, Permissions & Auditing, Java & JDBC Development
I can restrict access to my "test.html" via Apache security. I'm only using a simple user authentication htpasswd now. How can I use the user name entered for password verification in the cjac.cnf file. I wish to use something like the following: cjac.app."test".cmd= "rsh -l $USER_NAME -h unixbox unix_command" $(FGL_AUTHUSER) is obviously not applicable here. Thanks for any assistance wrt user access. Zion Mahangoo Raytheon Engineers and Constructors P.S. What options are available (if any) for editing data in a text field. Sent via Deja.com http://www.deja.com/ Before you buy.
On Wed, 01 Mar 2000 17:22:55 GMT, Zion Mahangoo <zkm@trac3000.ueci.com> wrote: >I can restrict access to my "test.html" via Apache security. I'm only >using a simple user authentication htpasswd now. > >How can I use the user name entered for password verification in the >cjac.cnf file. I wish to use something like the following: >cjac.app."test".cmd= "rsh -l $USER_NAME -h unixbox unix_command" >$(FGL_AUTHUSER) is obviously not applicable here. Why not? Ralf -- Van Roy's Law: ------------------------------------------------------- An unbreakable toy is useful for breaking other toys.
Well I may be wrong, I'm new to apache, but isn't $(FGL_AUTHUSER) the user that the apache server is being run under?? May be if I tell you what I have and want you may be able to show me the error of my approach/assumptions: My test setup is a simple one: Win '98 running Apache/1.3.6 (Win32) ApacheJServ/1.0 Connecting via "WINRSH.EXE" to a unix application server. All seems to work fine... The application I'm running on the Unix application server uses dbuserid() for application security. I want to do something like this in the cjac.cnf file: cjac.app."test".cmd= "winrsh -l $(USER_NAME) -h unixbox unix_command" where $(USER_NAME) comes from the username/password verification that I've implemented using the simple user authentication "htpasswd" method. I can not find where/if apache keeps user_name in a accessible variable. If so can I use it in the cjac.cnf file?? Right now "winrsh.exe -l zion -h application_server launch_app_shell_script" works great, application security limited by dbuserid() being zion. I only wish to replace the hard coded user name with a variable one. Thanks for the response and any further assistance you can provide. Regards, Zion Mahangoo Raytheon Engineers and Constructors In article <slrn8bstm7.qd3.ifxrlf@Ralf.bj-ig.de>, ifxrlf@bj-ig.de wrote: > On Wed, 01 Mar 2000 17:22:55 GMT, Zion Mahangoo <zkm@trac3000.ueci.com> wrote: > >I can restrict access to my "test.html" via Apache security. I'm only > >using a simple user authentication htpasswd now. > > > >How can I use the user name entered for password verification in the > >cjac.cnf file. I wish to use something like the following: > >cjac.app."test".cmd= "rsh -l $USER_NAME -h unixbox unix_command" > >$(FGL_AUTHUSER) is obviously not applicable here. > > Why not? > > Ralf > > -- > Van Roy's Law: ------------------------------------------------------- > An unbreakable toy is useful for breaking other toys. > Sent via Deja.com http://www.deja.com/ Before you buy.
On Thu, 02 Mar 2000 16:53:51 GMT, Zion Mahangoo <zkm@trac3000.ueci.com> wrote: >Well I may be wrong, I'm new to apache, but isn't $(FGL_AUTHUSER) the >user that the apache server is being run under?? No - it is set by the servlet to the name of the apache authenticated user. >I want to do something like this in the cjac.cnf file: >cjac.app."test".cmd= "winrsh -l $(USER_NAME) -h unixbox unix_command" >where $(USER_NAME) comes from the username/password verification that That is what FGL_AUTHUSER is for. Ralf -- Van Roy's Law: ------------------------------------------------------- An unbreakable toy is useful for breaking other toys.
Thanks Ralf for you great help. But this still leaves me with a problem. My entry: cjac.app."trac".arg = "-l $(FGL_AUTHUSER) -h unixbox \\"/usr/fgl2c/demo/runtest.sh $(FGL_GUISRVNUM)\\"" $(FGL_GUISRVNUM) brings in the a value into the cjac.cnf, but $(FGL_AUTHUSER) does not. As I said before I'm using simple authentication using "htaccess". Have I missed something in configuring the authentication, sevrlet, apache?? I greatly appreciate all the help..Thanks.. Regards, Zion Mahangoo Raytheon Engineers & Constructors. P.S. if it helps this is my .htaccess: AuthName "restricted stuff" AuthType Basic AuthUserFile "C:\\Program Files\\Apache Group\\Apache\\users" require valid-user These are the parts of my htpd.conf I used: <Directory "C:/Program Files/Apache Group/Apache/htdocs"> Options Indexes FollowSymLinks MultiViews AllowOverride AuthConfig Order allow,deny Allow from all </Directory> AccessFileName .htaccess <Files .htaccess> Order allow,deny Deny from all </Files> In article <slrn8btc2m.t38.ifxrlf@Ralf.bj-ig.de>, ifxrlf@bj-ig.de wrote: > On Thu, 02 Mar 2000 16:53:51 GMT, Zion Mahangoo <zkm@trac3000.ueci.com> wrote: > >Well I may be wrong, I'm new to apache, but isn't $(FGL_AUTHUSER) the > >user that the apache server is being run under?? > > No - it is set by the servlet to the name of the apache authenticated user. > > >I want to do something like this in the cjac.cnf file: > >cjac.app."test".cmd= "winrsh -l $(USER_NAME) -h unixbox unix_command" > >where $(USER_NAME) comes from the username/password verification that > > That is what FGL_AUTHUSER is for. > > Ralf > > -- > Van Roy's Law: ------------------------------------------------------- > An unbreakable toy is useful for breaking other toys. > Sent via Deja.com http://www.deja.com/ Before you buy.
In article <89mm3f$5vn$1@nnrp1.deja.com>, zkm@trac3000.ueci.com says... > Thanks Ralf for you great help. > But this still leaves me with a problem. My entry: > cjac.app."trac".arg = "-l $(FGL_AUTHUSER) -h unixbox > \\"/usr/fgl2c/demo/runtest.sh $(FGL_GUISRVNUM)\\"" > > $(FGL_GUISRVNUM) brings in the a value into the cjac.cnf, but > $(FGL_AUTHUSER) does not. I use the following cjac.app.*.env."REMOTEUSER" = "$(FGL_AUTHUSER)" and then I use REMOTEUSER. I forgot why, but I remember that there was some problems when using FGL_AUTHUSER. Or was that beta maybe, Ralf is the man to give definitive answer. Are you sure that the SERVLET is password protected? NOT the web page defining APPLET, but SERVLET, as in /servlets/cjac ? You can protect page too, but if servlet is not authorised, and since SERVLET is supposed to export FGL_AUTHUSER in first place, it would simly not receive user name from Apache for that location. -- Yours, Andrej Falout, http://www.falout.com ICQ 7628616 ++64.21.607517 #----------------------------------------------------------------- globals "std_disclaimer.4gl" Ask yourself just one question: ' Qu' m's se puede hacer y aprender ? - Propellerhead ReBirth RB-338 manual
On Fri, 3 Mar 2000 12:13:01 +1300, Andrej Falout <afalout@xtra.co.nz> wrote: > >> But this still leaves me with a problem. My entry: >> cjac.app."trac".arg = "-l $(FGL_AUTHUSER) -h unixbox >> \\"/usr/fgl2c/demo/runtest.sh $(FGL_GUISRVNUM)\\"" >> >> $(FGL_AUTHUSER) does not. > >cjac.app.*.env."REMOTEUSER" = "$(FGL_AUTHUSER)" > >and then I use REMOTEUSER. I forgot why, but I remember that there was >some problems when using FGL_AUTHUSER. Or was that beta maybe, The only know side effect is that your REMOTEUSER results in a real environment variable and $(FGL_AUTHUSER) is expanded before the command line is executed (it is expanded by the servlet - not by the shell). >Are you sure that the SERVLET is password protected? > >NOT the web page defining APPLET, but SERVLET, as in /servlets/cjac ? I think this is the problem. FGL_AUTHUSER is only set when the servlet is password protected. How you protect the start page is not relevant. Ralf -- Van Roy's Law: ------------------------------------------------------- An unbreakable toy is useful for breaking other toys.
Thanks Andrej and Ralf for you help. Yes I did not protect the servlet, only the start page. I removed security authentication for the page and tried to protect the servlet "cjac" in the "httpd.conf" file: <Files cjac> order allow,deny allow from all AuthType Basic AuthName "restricted servlets" AuthUserFile "C:\\Program Files\\Apache Group\\Apache\\users" require valid-user </Files> From my browser "http://myserver/servlets/cjac?TEST" brings up the password verification box. However, when I try to do it via the start page: <APPLET CODE="com.informix.gui.applet.CJA" ARCHIVE="cja.jar" WIDTH=650 HEIGHT=490 CODEBASE="\\clijava" <PARAM="bgimage" VALUE="\\clipart\\bg.gif"> <PARAM Name="AppKey" VALUE="trac"> </APPLET> There is no password verification, hence no $(FGL_AUTHUSER). I tried many permutations and combinations basing protection at the file and directory levels with the same results. The other notable entry in my "httpd.conf" file is: <Directory "C:/Program Files/Apache Group/Apache/htdocs"> Options Indexes FollowSymLinks MultiViews AllowOverride AuthConfig Order allow,deny Allow from all </Directory> What am I missing (I been missing quite a lot lately). Thanks for your greatly appreciated assistance. Regards, Zion Mahangoo Raytheon Engineers & Constructors. In article <slrn8bvmuu.29o.ifxrlf@Ralf.bj-ig.de>, ifxrlf@bj-ig.de wrote: > On Fri, 3 Mar 2000 12:13:01 +1300, Andrej Falout <afalout@xtra.co.nz> wrote: > > > >> But this still leaves me with a problem. My entry: > >> cjac.app."trac".arg = "-l $(FGL_AUTHUSER) -h unixbox > >> \\"/usr/fgl2c/demo/runtest.sh $(FGL_GUISRVNUM)\\"" > >> > >> $(FGL_AUTHUSER) does not. > > > >cjac.app.*.env."REMOTEUSER" = "$(FGL_AUTHUSER)" > > > >and then I use REMOTEUSER. I forgot why, but I remember that there was > >some problems when using FGL_AUTHUSER. Or was that beta maybe, > > The only know side effect is that your REMOTEUSER results in a real > environment variable and $(FGL_AUTHUSER) is expanded before the command > line is executed (it is expanded by the servlet - not by the shell). > > >Are you sure that the SERVLET is password protected? > > > >NOT the web page defining APPLET, but SERVLET, as in /servlets/cjac ? > > I think this is the problem. FGL_AUTHUSER is only set when the servlet > is password protected. How you protect the start page is not relevant. > > Ralf > > -- > Van Roy's Law: ------------------------------------------------------- > An unbreakable toy is useful for breaking other toys. > Sent via Deja.com http://www.deja.com/ Before you buy.
In article <8a1c5q$fh8$1@nnrp1.deja.com>, zkm@trac3000.ueci.com says... > Thanks Andrej and Ralf for you help. > Yes I did not protect the servlet, only the start page. > I removed security authentication for the page and tried to protect the > servlet "cjac" in the "httpd.conf" file: > <Files cjac> > order allow,deny > allow from all > AuthType Basic > AuthName "restricted servlets" > AuthUserFile "C:\\Program Files\\Apache Group\\Apache\\users" > require valid-user > </Files> ...big snip... probably because /servlets/cjac is a synonym, not an actual file location. Try "location" <Location /servlets/cjac> AuthType basic AuthName "restricted servlets" AuthUserFile "C:\\Program Files\\Apache Group\\Apache\\users" <Limit GET POST> require valid-user </Limit> </Location> HTH, -- Yours, Andrej Falout, http://www.falout.com ICQ 7628616 ++64.21.607517 #----------------------------------------------------------------- globals "std_disclaimer.4gl" Ask yourself just one question: ' Qu' m's se puede hacer y aprender ? - Propellerhead ReBirth RB-338 manual