+49 228 5552576-0


Access Control Lists

Restrict access to services and resources with the ACL feature of Membrane Monitor and Service Proxy. An ACL file allows a fine grained configuration of permissions.



Two steps are required to setup access control using Membrane.

1. Write an ACL File

The following sample declares permissions for some resources:

    <!-- Access to resources under  /open-source/ is permitted only for clients 
    within the IP range from to -->
    <resource uri="/open-source/*">
    <!-- The resources under /contact/ can only be accessed by localhost. -->
    <resource uri="/contact/*">
    <!-- Unrestricted access is granted to all clients for any other resource. -->
    <resource uri="*">
Listing 1: An ACL Sample File

The access control file is processed from top to bottom, therefore the order of the resource elements is important. Save the document to a file e.g. conf/acl.xml.

2. Engage the ACL Feature

Access control is activated by engaging the AccessControlInterceptor using the accessControl element. Only the aclFilename property pointing to your access control list file must be set. The interceptor bean definition looks like this:

				<spring:beans xmlns="http://membrane-soa.org/proxies/1/"
					xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
									    http://membrane-soa.org/proxies/1/ http://membrane-soa.org/schemas/proxies-1.xsd">
							<ruleMatching />
							<exchangeStore />
							<dispatching />
							<accessControl file="conf/acl.xml" />
							<userFeature />
							<httpClient />
						<serviceProxy port="8080">
Listing 2: Applying global AccessControl

ACL Example

Within the Membrane Service Proxy distribution under the examples/acl directory you can find an ACL sample showing how to setup ACL. It is preconfigured and uses it's own bean and rules configuration files. For a detailed explanation about this example please consult the README.txt file there.

See also

Copyright © 2008-2015 predic8 GmbH
Moltkestr. 40, 53173 Bonn, Tel. +49 (228) 555 25 76-0