Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, March 13, 2014

oracle.security.jps.JpsException in JDev 11.1.1.5 ADF

Friday, October 25, 2013

Logout from Single Sign On an ADF application

  <af:goLink text=' #{securityContext.authenticated ? "Logout" : "Login"}'
                             id="gl1"
                             destination='#{securityContext.authenticated ? "/adfAuthentication?logout=true&amp;end_url=/<context-root>/faces/start-page-of-the-app"  : "/adfAuthentication?success_url=/<context-root>/faces/start-page-of-the-app"} '/>

or

Use a Logout Button with an Action Listener method to avoid this exception while logout - oracle.adf.controller.ControllerException: ADFC-04008: The BindingContext on the session is null 

       
<af:commandButton text=" #{securityContext.authenticated ? &quot;Logout&quot; : &quot;Login&quot;}" id="cb7"
                                actionListener="#{backingBeanScope.backingBean.logout}"/>


       
    public void logout(ActionEvent actionEvent) {
        ExternalContext ectx = FacesContext.getCurrentInstance().getExternalContext(); 
              HttpServletRequest request = (HttpServletRequest)ectx.getRequest(); 
              String url = request.getContextPath() + 
                            "/adfAuthentication?logout=true&end_url=/faces/start-page-of-the-application"; 
              try 
              { 
                 ectx.redirect(url); 
              } 
              catch (Exception ex) 
              { 
                  System.out.println("Exception!! Logging out"+ex);
                 // Handle the exception 
              } 
    }


Session Invalidate Add before logging out : update required

Deploying ADF application with both HTTP Client Authentication(Public Key Certificate) and Form-Based Authentication

To Start with, implement security for the application with Form Based Authentication by specifying the login page, error page and default page




Then to configure  HTTP Client Authentication(Public Key Certificate) Go To -> Web.xml of the application and -> manually change <auth-method>FORM</auth-method> to <auth-method>CLIENT-CERT,FORM</auth-method> 




          Now if the application is deployed to single sign on, the application would be authenticated with HTTP Client Authentication(Public Key Certificate) . If the application is deployed as standalone  on LDAP it would require Form Based Authentication to login