blob: 0b610d64e02b76aff7e60731555fb20c8645028e [file] [log] [blame]
~~ $Id$
~~
~~ Licensed to the Apache Software Foundation (ASF) under one
~~ or more contributor license agreements. See the NOTICE file
~~ distributed with this work for additional information
~~ regarding copyright ownership. The ASF licenses this file
~~ to you under the Apache License, Version 2.0 (the
~~ "License"); you may not use this file except in compliance
~~ with the License. You may obtain a copy of the License at
~~
~~ http://www.apache.org/licenses/LICENSE-2.0
~~
~~ Unless required by applicable law or agreed to in writing,
~~ software distributed under the License is distributed on an
~~ "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
~~ KIND, either express or implied. See the License for the
~~ specific language governing permissions and limitations
~~ under the License.
~~
-----------
Security
-----------
Security
Tiles allows the visibility of a template, an attribute or a definition only
to selected roles.
* Allowing definitions
A definition can be allowed to be rendered only by selected roles:
* in XML definition files:
---------------------------------
<definition name="test.definition"
template="/layout/my-template.jsp role="myrole">
...
</definition>
---------------------------------
* in JSP pages, when inserting definitions:
---------------------------------
<tiles:insertDefinition name="test.definition" role="myrole" />
---------------------------------
* in JSP pages, when definining definitions:
---------------------------------
<tiles:definition name="test.definition"
template="/layout/my-template.jsp" role="myrole">
...
</tiles:definition>
---------------------------------
* Allowing attributes
An attribute can be allowed to be rendered only by selected roles:
* in XML definition files:
---------------------------------
<definition name="test.definition"
template="/layout/my-template.jsp>
<put-attribute name="header" value="/header.jsp" role="myrole" />
</definition>
---------------------------------
* in JSP pages, when inserting attributes:
---------------------------------
<tiles:insertAttribute name="header" role="myrole" />
---------------------------------
* in JSP pages, when putting attributes:
---------------------------------
<tiles:putAttribute name="header" value="/header.jsp" role="myrole" />
---------------------------------
* Allowing templates
Templates can be allowed to be rendered only by selected rows in JSP pages:
---------------------------------
<tiles:insertTemplate name="test.definition"
template="/layout/my-template.jsp" "role="myrole">
...
</tiles:insertTemplate>
---------------------------------