blob: 0c3133638ada7dbdde7c361ea2dadf0e9dc45770 [file] [log] [blame]
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Apache TomEE</title>
<meta name="description"
content="Apache TomEE is a lightweight, yet powerful, JavaEE Application server with feature rich tooling." />
<meta name="keywords" content="tomee,asf,apache,javaee,jee,shade,embedded,test,junit,applicationcomposer,maven,arquillian" />
<meta name="author" content="Luka Cvetinovic for Codrops" />
<link rel="icon" href="../../../favicon.ico">
<link rel="icon" type="image/png" href="../../../favicon.png">
<meta name="msapplication-TileColor" content="#80287a">
<meta name="theme-color" content="#80287a">
<link rel="stylesheet" type="text/css" href="../../../css/normalize.css">
<link rel="stylesheet" type="text/css" href="../../../css/bootstrap.css">
<link rel="stylesheet" type="text/css" href="../../../css/owl.css">
<link rel="stylesheet" type="text/css" href="../../../css/animate.css">
<link rel="stylesheet" type="text/css" href="../../../fonts/font-awesome-4.1.0/css/font-awesome.min.css">
<link rel="stylesheet" type="text/css" href="../../../fonts/eleganticons/et-icons.css">
<link rel="stylesheet" type="text/css" href="../../../css/jqtree.css">
<link rel="stylesheet" type="text/css" href="../../../css/idea.css">
<link rel="stylesheet" type="text/css" href="../../../css/cardio.css">
<script type="text/javascript">
var _gaq = _gaq || [];
_gaq.push(['_setAccount', 'UA-2717626-1']);
_gaq.push(['_setDomainName', 'apache.org']);
_gaq.push(['_trackPageview']);
(function() {
var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true;
ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js';
var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);
})();
</script>
</head>
<body>
<div class="preloader">
<img src="../../../img/loader.gif" alt="Preloader image">
</div>
<nav class="navbar">
<div class="container">
<div class="row"> <div class="col-md-12">
<!-- Brand and toggle get grouped for better mobile display -->
<div class="navbar-header">
<button type="button" class="navbar-toggle collapsed" data-toggle="collapse" data-target="#bs-example-navbar-collapse-1">
<span class="sr-only">Toggle navigation</span>
<span class="icon-bar"></span>
<span class="icon-bar"></span>
<span class="icon-bar"></span>
</button>
<a class="navbar-brand" href="/">
<span>
<img src="../../../img/logo-active.png">
</span>
Apache TomEE
</a>
</div>
<!-- Collect the nav links, forms, and other content for toggling -->
<div class="collapse navbar-collapse" id="bs-example-navbar-collapse-1">
<ul class="nav navbar-nav navbar-right main-nav">
<li><a href="../../../docs.html">Documentation</a></li>
<li><a href="../../../community/index.html">Community</a></li>
<li><a href="../../../security/security.html">Security</a></li>
<li><a href="../../../download-ng.html">Downloads</a></li>
</ul>
</div>
<!-- /.navbar-collapse -->
</div></div>
</div>
<!-- /.container-fluid -->
</nav>
<div id="main-block" class="container main-block">
<div class="row title">
<div class="col-md-12">
<div class='page-header'>
<h1>MicroProfile JWT Principal</h1>
</div>
</div>
</div>
<div class="row">
<div class="col-md-12">
<div id="preamble">
<div class="sectionbody">
<div class="paragraph">
<p>Este é um exemplo de como usar o MicroProfile JWT no TomEE, acessando o <code>Principal</code> no JsonWebToken.</p>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_executando_a_aplicação">Executando a aplicação:</h2>
<div class="sectionbody">
<div class="listingblock">
<div class="content">
<pre class="highlight"><code class="language-bash" data-lang="bash">mvn clean install tomee:run</code></pre>
</div>
</div>
<div class="paragraph">
<p>Este exemplo é uma aplicação CRUD para pedidos na loja.</p>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_requisitos_e_configuração">Requisitos e configuração</h2>
<div class="sectionbody">
<div class="paragraph">
<p>Para o uso do MicroProfile JWT, precisamos alterar o seguinte em nosso projeto:</p>
</div>
<div class="olist arabic">
<ol class="arabic">
<li>
<p>Adicione a dependência ao nosso arquivo <code>pom.xml</code>:</p>
<div class="listingblock">
<div class="content">
<pre class="highlight"><code class="language-xml" data-lang="xml">&lt;dependency&gt;
&lt;groupId&gt;org.eclipse.microprofile.jwt&lt;/groupId&gt;
&lt;artifactId&gt;microprofile-jwt-auth-api&lt;/artifactId&gt;
&lt;version&gt;${mp-jwt.version}&lt;/version&gt;
&lt;scope&gt;provided&lt;/scope&gt;
&lt;/dependency&gt;</code></pre>
</div>
</div>
</li>
<li>
<p>Anote nossa <code>Application.class</code> com <code>@LoginConfig(authMethod = "MP-JWT")</code></p>
</li>
<li>
<p>Forneça <code>public</code> and <code>private key</code> para autenticação. E especifique a localização da <code>public key</code> e do <code>issuer</code> no nosso arquivo <code>microprofile-config.properties</code>.</p>
<div class="listingblock">
<div class="content">
<pre class="highlight"><code class="language-properties" data-lang="properties">mp.jwt.verify.publickey.location=/publicKey.pem
mp.jwt.verify.issuer=https://example.com</code></pre>
</div>
</div>
</li>
<li>
<p>Defina <code>@RolesAllowed()</code> nos endpoints que queremos proteger.</p>
</li>
</ol>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_obtenção_do_jwt_principal">Obtenção do JWT Principal</h2>
<div class="sectionbody">
<div class="paragraph">
<p>Obtemos o <code>Principal</code> na classe MicroProfile <code>org.eclipse.microprofile.jwt.JsonWebToken</code>. De lá
podemos adquirir o nome de usuário e os grupos do usuário que está acessando o endpoint.</p>
</div>
<div class="listingblock">
<div class="content">
<pre class="highlight"><code class="language-java" data-lang="java">@Inject
private JsonWebToken jwtPrincipal;</code></pre>
</div>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_sobre_a_arquitetura_da_aplicação">Sobre a arquitetura da aplicação</h2>
<div class="sectionbody">
<div class="paragraph">
<p>A aplicação nos permite manipular pedidos com usuários específicos. Temos dois usuários: <code>Alice Wonder</code> e <code>John Doe</code>. Eles podem ler, criar, editar e excluir entradas específicas. E para cada criação, salvamos o usuário que criou o pedido. Caso um usuário edite a entrada, registramos que, acessando o <code>Principal</code> que enviou a solicitação ao nosso back-end.</p>
</div>
<div class="paragraph">
<p><code>alice-wonder-jwt.json</code></p>
</div>
<div class="listingblock">
<div class="content">
<pre class="highlight"><code class="language-json" data-lang="json">{
"iss": "https://example.com",
"upn": "alice",
"sub": "alice.wonder@example.com",
"name": "Alice Wonder",
"iat": 1516239022,
"groups": [
"buyer"
]
}</code></pre>
</div>
</div>
<div class="paragraph">
<p><code>john-doe-jwt.json</code></p>
</div>
<div class="listingblock">
<div class="content">
<pre class="highlight"><code class="language-json" data-lang="json">{
"iss": "https://example.com",
"upn": "john",
"sub": "john.doe@example.com",
"name": "John Doe",
"iat": 1516239022,
"groups": [
"merchant"
]
}</code></pre>
</div>
</div>
</div>
</div>
<div class="sect1">
<h2 id="_acesse_os_endpoints_com_jwt_token">Acesse os endpoints com JWT token</h2>
<div class="sectionbody">
<div class="paragraph">
<p>Acessamos os endpoints da nossa classe de teste criando um <code>JWT</code> com a ajuda do nosso <code>TokenUtils.generateJWTString(String jsonResource)</code>, que assina nossos dados do usuário no formato json com a ajuda do nossa chave <code>src/test/resources/privateKey.pem.</code></p>
</div>
<div class="paragraph">
<p>Também podemos gerar o novo <code>privateKey.pem</code> e <code>publicKey.pem</code> com o método <code>GenerateKeyUtils.generateKeyPair(String keyAlgorithm, int keySize)</code>.
== APIs Used</p>
</div>
<div class="ulist">
<ul>
<li>
<p><a href="../../../microprofile-2.0/javadoc/org/eclipse/microprofile/auth/LoginConfig.html">org.eclipse.microprofile.auth.LoginConfig</a></p>
</li>
<li>
<p><a href="../../../microprofile-2.0/javadoc/org/eclipse/microprofile/jwt/Claims.html">org.eclipse.microprofile.jwt.Claims</a></p>
</li>
<li>
<p><a href="../../../microprofile-2.0/javadoc/org/eclipse/microprofile/jwt/JsonWebToken.html">org.eclipse.microprofile.jwt.JsonWebToken</a></p>
</li>
<li>
<p><a href="../../../microprofile-2.0/javadoc/org/eclipse/microprofile/rest/client/inject/RegisterRestClient.html">org.eclipse.microprofile.rest.client.inject.RegisterRestClient</a></p>
</li>
<li>
<p><a href="../../../microprofile-2.0/javadoc/org/eclipse/microprofile/rest/client/inject/RestClient.html">org.eclipse.microprofile.rest.client.inject.RestClient</a></p>
</li>
<li>
<p><a href="../../../jakartaee-8.0/javadoc/javax/annotation/PostConstruct.html">javax.annotation.PostConstruct</a></p>
</li>
<li>
<p><a href="../../../jakartaee-8.0/javadoc/javax/annotation/security/RolesAllowed.html">javax.annotation.security.RolesAllowed</a></p>
</li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
<footer>
<div class="container">
<div class="row">
<div class="col-sm-6 text-center-mobile">
<h3 class="white">Be simple. Be certified. Be Tomcat.</h3>
<h5 class="light regular light-white">"A good application in a good server"</h5>
<ul class="social-footer">
<li><a href="https://www.facebook.com/ApacheTomEE/"><i class="fa fa-facebook"></i></a></li>
<li><a href="https://twitter.com/apachetomee"><i class="fa fa-twitter"></i></a></li>
<li><a href="https://plus.google.com/communities/105208241852045684449"><i class="fa fa-google-plus"></i></a></li>
</ul>
</div>
<div class="col-sm-6 text-center-mobile">
<div class="row opening-hours">
<div class="col-sm-3 text-center-mobile">
<h5><a href="../../../latest/docs/" class="white">Documentation</a></h5>
<ul class="list-unstyled">
<li><a href="../../../latest/docs/admin/configuration/index.html" class="regular light-white">How to configure</a></li>
<li><a href="../../../latest/docs/admin/file-layout.html" class="regular light-white">Dir. Structure</a></li>
<li><a href="../../../latest/docs/developer/testing/index.html" class="regular light-white">Testing</a></li>
<li><a href="../../../latest/docs/admin/cluster/index.html" class="regular light-white">Clustering</a></li>
</ul>
</div>
<div class="col-sm-3 text-center-mobile">
<h5><a href="../../../latest/examples/" class="white">Examples</a></h5>
<ul class="list-unstyled">
<li><a href="../../../latest/examples/simple-cdi-interceptor.html" class="regular light-white">CDI Interceptor</a></li>
<li><a href="../../../latest/examples/rest-cdi.html" class="regular light-white">REST with CDI</a></li>
<li><a href="../../../latest/examples/ejb-examples.html" class="regular light-white">EJB</a></li>
<li><a href="../../../latest/examples/jsf-managedBean-and-ejb.html" class="regular light-white">JSF</a></li>
</ul>
</div>
<div class="col-sm-3 text-center-mobile">
<h5><a href="../../../community/index.html" class="white">Community</a></h5>
<ul class="list-unstyled">
<li><a href="../../../community/contributors.html" class="regular light-white">Contributors</a></li>
<li><a href="../../../community/social.html" class="regular light-white">Social</a></li>
<li><a href="../../../community/sources.html" class="regular light-white">Sources</a></li>
</ul>
</div>
<div class="col-sm-3 text-center-mobile">
<h5><a href="../../../security/index.html" class="white">Security</a></h5>
<ul class="list-unstyled">
<li><a href="http://apache.org/security" target="_blank" class="regular light-white">Apache Security</a></li>
<li><a href="http://apache.org/security/projects.html" target="_blank" class="regular light-white">Security Projects</a></li>
<li><a href="http://cve.mitre.org" target="_blank" class="regular light-white">CVE</a></li>
</ul>
</div>
</div>
</div>
</div>
<div class="row bottom-footer text-center-mobile">
<div class="col-sm-12 light-white">
<p>Copyright &copy; 1999-2016 The Apache Software Foundation, Licensed under the Apache License, Version 2.0. Apache TomEE, TomEE, Apache, the Apache feather logo, and the Apache TomEE project logo are trademarks of The Apache Software Foundation. All other marks mentioned may be trademarks or registered trademarks of their respective owners.</p>
</div>
</div>
</div>
</footer>
<!-- Holder for mobile navigation -->
<div class="mobile-nav">
<ul>
<li><a hef="../../../latest/docs/admin/index.html">Administrators</a>
<li><a hef="../../../latest/docs/developer/index.html">Developers</a>
<li><a hef="../../../latest/docs/advanced/index.html">Advanced</a>
<li><a hef="../../../community/index.html">Community</a>
</ul>
<a href="#" class="close-link"><i class="arrow_up"></i></a>
</div>
<!-- Scripts -->
<script src="../../../js/jquery-1.11.1.min.js"></script>
<script src="../../../js/owl.carousel.min.js"></script>
<script src="../../../js/bootstrap.min.js"></script>
<script src="../../../js/wow.min.js"></script>
<script src="../../../js/typewriter.js"></script>
<script src="../../../js/jquery.onepagenav.js"></script>
<script src="../../../js/tree.jquery.js"></script>
<script src="../../../js/highlight.pack.js"></script>
<script src="../../../js/main.js"></script>
</body>
</html>