English 中文(简体)
无会话的验证、授权和用户跟踪
原标题:Authentication, Authorisation & User Tracking without Sessions

使用 Java Web 应用程序( JSP/Servilles, no EJBs),在不使用HttpSession s的情况下,验证用户和授权其行动的最佳办法是什么?

这种做法/问题的原因是我希望我们的申请仍然无国籍,所以我不需要在地理上分散的 < /em > 数据中心内复制完整的会议,而且可以更容易地从集群中添加和删除服务器。

谢谢 谢谢

最佳回答

成功登录后生成标记, 每个请求只验证此标记。 当然, 标记需要复制, 但不应超过100 字节的数据, 因此与典型的 < code> Htpsession 重量相比, 性能影响会相当低 。

问题回答

公钥基础设施 。 创建您自己的 CA, 签名并颁发用户证书 。 启用客户端- auth 连接 。

您可以使用“ 隐藏窗体字段” 或“ URL 重写” 。





相关问题
Spring Properties File

Hi have this j2ee web application developed using spring framework. I have a problem with rendering mnessages in nihongo characters from the properties file. I tried converting the file to ascii using ...

Logging a global ID in multiple components

I have a system which contains multiple applications connected together using JMS and Spring Integration. Messages get sent along a chain of applications. [App A] -> [App B] -> [App C] We set a ...

Java Library Size

If I m given two Java Libraries in Jar format, 1 having no bells and whistles, and the other having lots of them that will mostly go unused.... my question is: How will the larger, mostly unused ...

How to get the Array Class for a given Class in Java?

I have a Class variable that holds a certain type and I need to get a variable that holds the corresponding array class. The best I could come up with is this: Class arrayOfFooClass = java.lang....

SQLite , Derby vs file system

I m working on a Java desktop application that reads and writes from/to different files. I think a better solution would be to replace the file system by a SQLite database. How hard is it to migrate ...

热门标签