如何限制Tomcat Manager用户访问权限?创建仅可读权限用户
Hi Ashwini, great question! Creating a read-only user for Tomcat Manager that can view application details but can’t perform deploy/undeploy/reload operations requires adjusting two key configuration files. Let’s walk through the steps:
1. 配置用户与角色(conf/tomcat-users.xml)
First, we’ll define custom roles and assign them to users in Tomcat’s core user configuration file.
Open conf/tomcat-users.xml and add the following inside the <tomcat-users> tag:
<!-- Define custom roles --> <role rolename="manager-readonly"/> <!-- For read-only access to app list/status --> <role rolename="manager-deploy"/> <!-- For deploy/undeploy/reload permissions --> <!-- Read-only user: can view apps but can't modify them --> <user username="readonly_user" password="your_secure_password" roles="manager-readonly,manager-status"/> <!-- Full-access admin user (for reference) --> <user username="admin" password="admin_secure_password" roles="manager-gui,manager-deploy,manager-script,manager-jmx"/>
manager-readonly: We’ll map this role to allow viewing app lists and status pages.manager-status: Ensures access to the server status dashboard.- Important: Use strong, unique passwords for production environments.
2. 调整Manager应用的权限约束(webapps/manager/WEB-INF/web.xml)
By default, the manager-gui role grants full access to the HTML interface (including deploy/undeploy). We need to split the security constraints to restrict modification operations to users with the manager-deploy role.
Open webapps/manager/WEB-INF/web.xml and replace the existing <security-constraint> blocks for the HTML interface with these:
<!-- Allow read-only users to view app lists and status --> <security-constraint> <web-resource-collection> <web-resource-name>Manager Read Access</web-resource-name> <url-pattern>/html/list</url-pattern> <url-pattern>/html/status</url-pattern> <url-pattern>/status/*</url-pattern> </web-resource-collection> <auth-constraint> <role-name>manager-readonly</role-name> <role-name>manager-gui</role-name> </auth-constraint> </security-constraint> <!-- Restrict deploy/undeploy/reload operations to authorized users only --> <security-constraint> <web-resource-collection> <web-resource-name>Manager Deploy Access</web-resource-name> <url-pattern>/html/upload</url-pattern> <url-pattern>/html/undeploy</url-pattern> <url-pattern>/html/reload</url-pattern> <url-pattern>/html/start</url-pattern> <url-pattern>/html/stop</url-pattern> </web-resource-collection> <auth-constraint> <role-name>manager-deploy</role-name> <role-name>manager-gui</role-name> </auth-constraint> </security-constraint> <!-- Grant full HTML interface access to admin users (excluding already defined URLs) --> <security-constraint> <web-resource-collection> <web-resource-name>Full HTML Manager Access</web-resource-name> <url-pattern>/html/*</url-pattern> <url-pattern>!/html/list</url-pattern> <url-pattern>!/html/status</url-pattern> <url-pattern>!/html/upload</url-pattern> <url-pattern>!/html/undeploy</url-pattern> <url-pattern>!/html/reload</url-pattern> <url-pattern>!/html/start</url-pattern> <url-pattern>!/html/stop</url-pattern> </web-resource-collection> <auth-constraint> <role-name>manager-gui</role-name> </auth-constraint> </security-constraint>
3. (可选)允许远程访问Manager应用
By default, Tomcat restricts Manager access to localhost. If you need to access it remotely:
- Open
webapps/manager/META-INF/context.xml - Modify or comment out the
RemoteAddrValveblock to allow your IP range:
<!-- Example: Allow access from 192.168.1.0/24 and localhost --> <Valve className="org.apache.catalina.valves.RemoteAddrValve" allow="127\.\d+\.\d+\.\d+|::1|0:0:0:0:0:0:0:1|192\.168\.1\.\d+" />
Note: Avoid commenting this out entirely in production environments—always restrict access to trusted IPs.
4. 重启Tomcat
Save all changes and restart your Tomcat server for the configurations to take effect.
Now, when you log in with the readonly_user account, you’ll be able to view the list of deployed applications and server status, but all deploy/undeploy/reload buttons will be inaccessible (or you’ll get a 403 Forbidden error if you try to access those URLs directly).
内容的提问来源于stack exchange,提问作者Ashwini

