AuthZForce适配静态页面访问控制需求咨询及实现协助请求
Can AuthZForce Meet My Static Page Time-Based Access Control Needs on Tomcat?
Absolutely, AuthZForce is a perfect match for your use case—it’s built specifically to handle fine-grained access control using the PEP/PDP model, including time-based restrictions for static content. Let’s walk through a complete, step-by-step implementation from scratch:
Step 1: Spin Up the AuthZForce PDP Server
- Grab the latest standalone AuthZForce Core Server distribution and unzip it.
- Launch the server: run
./bin/authzforce-core-server-start.shon Linux/macOS, or.\bin\authzforce-core-server-start.baton Windows. - Confirm it’s working by hitting
http://localhost:8080/authzforce-ce/domainsin your browser—you’ll get a JSON response if the PDP API is up and running.
Step 2: Create a Time-Based Access Policy
- First, create a domain (a container for your policies) via the REST API. Send a POST request to
http://localhost:8080/authzforce-ce/domainswith this JSON body:{ "name": "StaticPageAccessDomain", "description": "Controls time-based access to Tomcat static pages" } - Save the domain ID from the response, then create your time-restriction policy by sending a POST to
http://localhost:8080/authzforce-ce/domains/{YOUR_DOMAIN_ID}/policieswith this policy (note: this uses UTC time—adjust the09:00:00and17:00:00values if you need a different timezone):{ "id": "WorkingHoursAccessPolicy", "name": "Allow Static Page Access Only 9AM-5PM", "target": { "anyOf": [ { "allOf": [ { "resource": {"id": {"equals": "http://your-tomcat-server/static/**"}} } ] } ] }, "rules": [ { "id": "PermitDuringWorkingHours", "effect": "PERMIT", "condition": { "function": { "functionId": "urn:oasis:names:tc:xacml:1.0:function:time-in-range", "arguments": [ {"attributeDesignator": {"attributeId": "urn:oasis:names:tc:xacml:1.0:environment:current-time", "category": "urn:oasis:names:tc:xacml:3.0:attribute-category:environment", "dataType": "http://www.w3.org/2001/XMLSchema#time"}}, {"attributeValue": {"dataType": "http://www.w3.org/2001/XMLSchema#time", "value": "09:00:00"}}, {"attributeValue": {"dataType": "http://www.w3.org/2001/XMLSchema#time", "value": "17:00:00"}} ] } } }, { "id": "DenyAllOtherRequests", "effect": "DENY" } ] }
Step 3: Add the AuthZForce PEP Valve to Tomcat
- Tomcat uses valves to intercept requests, and AuthZForce has a ready-made PEP valve for this. Download the AuthZForce Tomcat PEP Valve JAR and its dependencies, then drop them into Tomcat’s
libfolder. - Configure the valve in your Tomcat
conf/server.xml—add this inside the<Host>block (or<Context>block if you want to restrict it to a specific app):<Valve className="org.ow2.authzforce.tomcat.AuthzForceValve" pdpUrl="http://localhost:8080/authzforce-ce/domains/{YOUR_DOMAIN_ID}/pdp" clientAuth="false" sendXacmlRequest="true"/> - Restart Tomcat to apply the changes.
Step 4: Test the Access Restriction
- Try loading your static page before 9 AM or after 5 PM—you should get a 403 Forbidden error.
- Access it during working hours, and it should load normally.
About Private 1:1 Assistance
Stack Overflow’s public Q&A is the go-to for community support, but if you need more personalized help, you can reach out to AuthZForce contributors via their GitHub Discussions page. Many experienced users and maintainers are happy to assist if you share clear details about your setup and any specific issues you run into.
内容的提问来源于stack exchange,提问作者terence
相关产品推荐
相关产品推荐

