6 Replies Latest reply on Oct 24, 2007 4:24 PM by Anil Saldanha

    Generate SSOID in WebAuthentication

    Stefan Guilhen Apprentice

      As stated on issue http://jira.jboss.com/jira/browse/JBAS-4424, the org.jboss.web.tomcat.security.login.WebAuthentication class should be capable of generating a ssoid and setting it on the session when the user has configured the SingleSignOn valve.

      The idea is to get a reference to the SingleSignOn valve and invoke its methods to associate the authenticated Principal to the ssoid, just like the AuthenticatorBase does. However, the methods that we need to call are protected (register, associate, update, etc), so we can't simply delegate the SSO functionality to the SingleSignOn valve unless we relax the method's access to public in JBossWeb. Can we do that?