]> git.argeo.org Git - lgpl/argeo-commons.git/blobdiff - server/modules/org.argeo.jackrabbit.webapp/WEB-INF/security-filters.xml
Fix missing bean in security filters
[lgpl/argeo-commons.git] / server / modules / org.argeo.jackrabbit.webapp / WEB-INF / security-filters.xml
index 5d431922205d276e9f9e924625b7ded1e193dc11..ee9c6aa0d501adcbea60cbc00fb1753babcb559f 100644 (file)
@@ -9,9 +9,9 @@
        <bean id="springSecurityFilterChain" class="org.springframework.security.util.FilterChainProxy">
                <sec:filter-chain-map path-type="ant">
                        <sec:filter-chain pattern="/webdav/**"
-                               filters="x509,basic,rememberMe,exception,interceptor" />
+                               filters="session,x509,basic,rememberMe,exception,interceptor" />
                        <sec:filter-chain pattern="/remoting/**"
-                               filters="x509,basic,rememberMe,exception,interceptor" />
+                               filters="x509,basic,anonymous,exception,interceptor" />
                        <sec:filter-chain pattern="/public/**"
                                filters="anonymous,exception,interceptorPublic" />
                        <sec:filter-chain pattern="/pub/**"
@@ -28,7 +28,6 @@
                        <value>
                                PATTERN_TYPE_APACHE_ANT
                                /*/*/*/**=ROLE_USER,ROLE_ADMIN
-                               /**=ROLE_ANONYMOUS
                        </value>
                </property>
        </bean>
                </property>
        </bean>
 
-       <!-- Integrates the authentication information in the http sessions
+       <!-- Integrates the authentication information in the http sessions -->
        <bean id="session"
                class="org.springframework.security.context.HttpSessionContextIntegrationFilter">
                <property name="allowSessionCreation" value="false" />
        </bean>
- -->
+
        <!-- Processes logouts, removing both session informations and the remember-me 
                cookie from the browser -->
        <bean id="logout" class="org.springframework.security.ui.logout.LogoutFilter">