Make data admin log-in more robust and easier to use.
[lgpl/argeo-commons.git] / org.argeo.cms / src / org / argeo / cms / internal / kernel / jaas.cfg
index 4f647cf8a667a38f8f4f2a06a8bc2237310a2862..e54277a3c73fcb1b9dbcc2a4fe5c1908db9f3ad1 100644 (file)
@@ -1,33 +1,28 @@
 USER {
-    org.argeo.cms.auth.NodeContextLoginModule requisite;
-    org.argeo.cms.auth.UserAdminLoginModule requisite;
-    org.argeo.cms.auth.NodeUserLoginModule requisite;
+    org.argeo.cms.auth.HttpSessionLoginModule sufficient;
+    org.argeo.cms.auth.IdentLoginModule optional;
+    org.argeo.cms.auth.UserAdminLoginModule sufficient;
 };
 
 ANONYMOUS {
-    org.argeo.cms.auth.NodeContextLoginModule requisite;
-    org.argeo.cms.auth.UserAdminLoginModule requisite anonymous=true;
-    org.argeo.cms.auth.NodeUserLoginModule requisite;
+    org.argeo.cms.auth.HttpSessionLoginModule sufficient;
+    org.argeo.cms.auth.AnonymousLoginModule sufficient;
 };
 
-SYSTEM {
-    org.argeo.security.core.SystemLoginModule requisite;
+DATA_ADMIN {
+    org.argeo.node.DataAdminLoginModule requisite;
 };
 
-KERNEL {
-    com.sun.security.auth.module.UnixLoginModule requisite;
-    com.sun.security.auth.module.KeyStoreLoginModule requisite keyStoreURL="${osgi.instance.area}/node.p12" keyStoreType=PKCS12 keyStoreProvider=BC;
-    org.argeo.cms.internal.auth.KernelLoginModule requisite;
+NODE {
+    org.argeo.node.DataAdminLoginModule requisite;
 };
 
 KEYRING {
-    org.argeo.security.crypto.KeyringLoginModule required;
+    org.argeo.cms.auth.KeyringLoginModule required;
 };
 
 SINGLE_USER {
-    com.sun.security.auth.module.UnixLoginModule requisite;
-    org.argeo.cms.internal.auth.SingleUserLoginModule requisite;
-    org.springframework.security.authentication.jaas.SecurityContextLoginModule requisite;
+    org.argeo.cms.auth.SingleUserLoginModule requisite;
 };
 
 Jackrabbit {