November 2017
Intermediate to advanced
542 pages
14h 24m
English
We'll fully explore the advanced authorization techniques later in Chapter 11, Fine-Grained Access Control, however, it's important to realize that it's possible to differentiate access rules based on whether or not an authenticated session was remembered.
Let's assume we want to limit users trying to access the H2 admin console to administrators who have been authenticated using a username and password. This is similar to the behavior found in other major consumer-focused commerce sites, which restrict access to the elevated portions of the site until a password is entered. Keep in mind that every site is different, so don't blindly apply such rules to your secure site. For our sample application, we'll ...
Read now
Unlock full access