Class BasicHttpAuthenticationFilter

java.lang.Object
All Implemented Interfaces:
javax.servlet.Filter, org.apache.shiro.lang.util.Nameable, PathConfigProcessor

Requires the requesting user to be authenticated for the request to continue, and if they're not, requires the user to login via the HTTP Basic protocol-specific challenge. Upon successful login, they're allowed to continue on to the requested resource/url.

This implementation is a 'clean room' Java implementation of Basic HTTP Authentication specification per RFC 2617.

Basic authentication functions as follows:

  1. A request comes in for a resource that requires authentication.
  2. The server replies with a 401 response status, sets the WWW-Authenticate header, and the contents of a page informing the user that the incoming resource requires authentication.
  3. Upon receiving this WWW-Authenticate challenge from the server, the client then takes a username and a password and puts them in the following format:

    username:password

  4. This token is then base 64 encoded.
  5. The client then sends another request for the same resource with the following header:

    Authorization: Basic Base64_encoded_username_and_password

The AccessControlFilter.onAccessDenied(javax.servlet.ServletRequest, javax.servlet.ServletResponse) method will only be called if the subject making the request is not authenticated
Since:
0.9
See Also: