13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5.3 Assigning EJB method permissionsSession and entity bean methods can be secured by preventing access to all butmembers of the security roles that need to access those methods. These methodpermissions can be applied using either the Application Assembly Tool or the<strong>WebSphere</strong> Studio.The method permissions are included in the application deployment descriptorfile ejb-jar.xml. The following example shows the XML elements which wouldallow members of the manager role to call all methods in the BranchAccountEJB, all Local Home methods in the CustomerAccount EJB, as well as thecreate() and remove() methods in the Consultation EJB.Example 5-1 Method permissions in the ejb-jar.xml filemanager method permissions:+:managerConsultationHomecreateBranchAccount*ConsultationHomeremovejavax.ejb.HandleCustomerAccountLocalHome*76 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!