Skip to main content
Jump to: navigation, search


< EclipseLink‎ | Release‎ | 2.4.0/JPA-RS
Revision as of 13:35, 14 May 2012 by (Talk | contribs) (JPA-RS Security)

JPA-RS Security

JPA-RS does not implement any security within its service methods. Users wishing to use JPA-RS within production application should secure access to the JPA-RS services using standard URL pattern security policies. This page illustrates how this can be done.

Securing JPA-RS in GlassFish

The following is an example of how JPA-RS can be secured within an application using standard Java EE configuration combined with the server specific security.

The web application that adds JPA-RS through its inclusion as a web-fragment by placing the JPA-RS libraryy in WEB-INF/lib can also augment their web.xml to control access to the JPA-RS service. An example of this woul look like:

<!-- Securing JPA-RS  -->
	<display-name>JPA-RS Security</display-name>

This configuration will limit all access to JPA-RS to container configured users who have the JPA-RS security role.

GlassFish: sun-web.xml

Within the GlassFish server the additional mapping from Java EE security role to the GlassFish secuity group is required.


Back to the top