Presently working on WFCORE-4360 adding support for expression resolution
backed by a credential store - the main barrier is going to be the solution
to bridge expression resolution with a subsystem provided component.
I am wondering if the following is going to be viable to support a
configurable expression resolver from a subsystem.
I see the RuntimeExpressionResolver is created very early in the boot
process, however at the time it is created the CapabilityRegistry is also
available. This is making me think if the CapabilityRegistry can be passed
in to the RuntimeExpressionResolver.
I would then imagine the resource handling expression resolution would
register a non-dynamic capability which exposes an expression resolver
runtime API. This in turn may also need to cross reference a credential
store which would also need to be accessible using the runtime API of a
At the time of expression resolution the RuntimeExpressionResolver would
then check the CapabilityRegistry to see if an expression resolver has been
registered and attempt to use it falling back to vault then default
ModelNode resolution if it does not resolve the expression.
Using a runtime API I suspect I would likely need to trigger the
initialisation of these APIs at the start of Stage.RUNTIME - that looks
feasible by adding a stage to Stage.RUNTIME with addFirst test to true -
maybe to be safe these should also start on demand based on first access.
There is ws deployment failure issue which is caused by Webservice
subsystem doesn't correctly get mapped elytron security domain from web
deployment's default "other"
application security domain. I tried to fix this by reading Elytron
security domain from Undertow started services, but it looks now
ApplicationSecurityDomainService is private static and it doesn't provide a
getter which allows to get Elytron security domain. Webservice subsystem
requires an Undertow service like ApplicationSecurityDomainService
started by EJB subsystem to read the Elytron security domain. Is it doable
to change Undertow's ApplicationSecurityDomainService to provide mapped
security domain ? Or any better approach to get the mapped Elytron domain ?
I have submitted a PR to enable the use of a cool ASCII banner during WildFly startup.
The banner content is externalized to a banner.txt file and removing that file or its content is supported.
What do you think about this ?
6:37:53,123 INFO [org.jboss.modules] (main) JBoss Modules version 1.10.0.Final
16:37:53,587 INFO [org.jboss.msc] (main) JBoss MSC version 1.4.11.Final
16:37:53,594 INFO [org.jboss.threads] (main) JBoss Threads version 2.3.3.Final
16:37:53,706 INFO [org.jboss.as] (MSC service thread 1-2) WFLYSRV0049: WildFly Core 12.0.0.Beta2-SNAPSHOT (WildFly Core
_ ___ __ __________ ______
| | / (_) /___/ / ____/ /_ __ / ____/___ ________
| | /| / / / / __ / /_ / / / / / / / / __ \/ ___/ _ \
| |/ |/ / / / /_/ / __/ / / /_/ / / /___/ /_/ / / / __/
|__/|__/_/_/\__,_/_/ /_/\__, / \____/\____/_/ \___/
16:37:54,319 INFO [org.wildfly.security] (ServerService Thread Pool -- 6) ELY00001: WildFly Elytron version 1.11.3.Final