[Red Hat JIRA] (WFLY-13889) Ongoing review of modules depending on PicketBox
by Brian Stansberry (Jira)
[ https://issues.redhat.com/browse/WFLY-13889?page=com.atlassian.jira.plugi... ]
Brian Stansberry updated WFLY-13889:
------------------------------------
Fix Version/s: 23.0.0.Beta1
(was: 22.0.0.Beta1)
> Ongoing review of modules depending on PicketBox
> ------------------------------------------------
>
> Key: WFLY-13889
> URL: https://issues.redhat.com/browse/WFLY-13889
> Project: WildFly
> Issue Type: Task
> Components: Security
> Reporter: Darran Lofthouse
> Assignee: Darran Lofthouse
> Priority: Major
> Fix For: 23.0.0.Beta1
>
>
> This follows up from WFLY-13679, ongoing work is needed to ensure PicketBox is not needed at all. The PicketBox module depends on APIs removed in Java 14 so we need to be able to eliminate it completely if legacy security it not being used.
> At the same time some subsystems are defaulting to legacy security with additional configuration being required to force configuration over to an Elytron configuration, in some cases this applies even if the underlying configuration is not using security at all such as JCA resource adaptors.
> We should be looking at what we can do to detect the presence of legacy security and now if not provisioned we should be able to default to Elytron based security.
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
5 years, 7 months
[Red Hat JIRA] (WFLY-14033) app-client unable to inject EJB unless also deployed locally to app client process
by Brian Stansberry (Jira)
[ https://issues.redhat.com/browse/WFLY-14033?page=com.atlassian.jira.plugi... ]
Brian Stansberry updated WFLY-14033:
------------------------------------
Fix Version/s: 23.0.0.Beta1
(was: 22.0.0.Beta1)
> app-client unable to inject EJB unless also deployed locally to app client process
> ----------------------------------------------------------------------------------
>
> Key: WFLY-14033
> URL: https://issues.redhat.com/browse/WFLY-14033
> Project: WildFly
> Issue Type: Bug
> Components: Application Client
> Reporter: Darran Lofthouse
> Priority: Major
> Fix For: 23.0.0.Beta1
>
>
> The current app-client quickstart uses a single ear for both server side and client side, this did not make sense as it means the EJBs are also deployed to the client process even though the client process is invoking remote EJBs exclusively.
> I have attempted some refactoring to make the quickstart clearer so users can see the server side requirement and the client side requirement:
> https://github.com/darranl/wildfly-quickstart/tree/WFLY-14027
> The problem is starting app-client now fails with this error:
> {code}
> Caused by: org.jboss.as.server.deployment.DeploymentUnitProcessingException: WFLYEJB0406: No EJB found with interface of type 'org.jboss.as.quickstarts.appclient.server.api.StatelessSession' for binding org.jboss.as.quickstarts.appclient.acc.client.Main/slsb
> at org.jboss.as.ejb3.deployment.processors.EjbInjectionSource.getResourceValue(EjbInjectionSource.java:90)
> at org.jboss.as.ee.component.deployers.ModuleJndiBindingProcessor.addJndiBinding(ModuleJndiBindingProcessor.java:271)
> at org.jboss.as.ee.component.deployers.ModuleJndiBindingProcessor$1.handle(ModuleJndiBindingProcessor.java:242)
> at org.jboss.as.ee.component.ClassDescriptionTraversal.run(ClassDescriptionTraversal.java:54)
> at org.jboss.as.ee.component.deployers.ModuleJndiBindingProcessor.processClassConfigurations(ModuleJndiBindingProcessor.java:246)
> at org.jboss.as.ee.component.deployers.ModuleJndiBindingProcessor.deploy(ModuleJndiBindingProcessor.java:160)
> at org.jboss.as.server.deployment.DeploymentUnitPhaseService.start(DeploymentUnitPhaseService.java:182) [wildfly-server-14.0.0.Beta1.jar:14.0.0.Beta1]
> ... 8 more
> {code}
> This feels as though the injection should either be a proxy which has not yet connected to the remote process or should connect to the remote process first to identify the available beans.
> The reason for delayed connection may be to enable authentication before the application uses the EJBs but deploying server side components on the client doesn't feel like the correct solution.
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
5 years, 7 months
[Red Hat JIRA] (WFLY-14123) Add OSGI Headers for jboss-ciient.jar
by Brian Stansberry (Jira)
[ https://issues.redhat.com/browse/WFLY-14123?page=com.atlassian.jira.plugi... ]
Brian Stansberry updated WFLY-14123:
------------------------------------
Fix Version/s: 23.0.0.Beta1
(was: 22.0.0.Beta1)
> Add OSGI Headers for jboss-ciient.jar
> -------------------------------------
>
> Key: WFLY-14123
> URL: https://issues.redhat.com/browse/WFLY-14123
> Project: WildFly
> Issue Type: Bug
> Components: Build System
> Reporter: Darran Lofthouse
> Priority: Major
> Fix For: 23.0.0.Beta1
>
>
> Headers such as the following should be added:
> {code:java}
> Bundle-ManifestVersion: 2
> Bundle-SymbolicName: org.jboss.client
> Bundle-Version: 1.0
> Bundle-Name: Test
> ExtensionFragment-Host: org.openjdk.jmc.rjmxExport-
> Package: *
> Automatic-Module-Name: org.jboss.client {code}
> The reason for this change is so the jar can be copied to a Java Mission Control folder
> {{/path/to/jmc/dropins/ and these updates will correct the class loading enabling the remoting-jmx connection to be established.}}
>
>
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
5 years, 7 months
[Red Hat JIRA] (WFLY-13706) Support a Galleon feature pack to install Keycloak adapters
by Brian Stansberry (Jira)
[ https://issues.redhat.com/browse/WFLY-13706?page=com.atlassian.jira.plugi... ]
Brian Stansberry updated WFLY-13706:
------------------------------------
Fix Version/s: 22.0.0.Final
(was: 22.0.0.Beta1)
> Support a Galleon feature pack to install Keycloak adapters
> -----------------------------------------------------------
>
> Key: WFLY-13706
> URL: https://issues.redhat.com/browse/WFLY-13706
> Project: WildFly
> Issue Type: Feature Request
> Components: Documentation, Security, Test Suite
> Reporter: Darran Lofthouse
> Assignee: Darran Lofthouse
> Priority: Major
> Fix For: 22.0.0.Final
>
>
> In conjunction with the bootable jar support currently being developed this feature request is to cover support for Keycloak client side adapter installation integrated with the Elytron security subsystem.
> The main feature pack is anticipated to be delivered by the Keycloak project, however as this is specifically for use with WildFly we likely need WildFly documentation and possibly test cases so this Jira issue to to cover tasks required within WildFly.
>
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
5 years, 7 months