Prev Next

API / Apache Wicket Interview questions

How do you enforce authorization/roles in a Wicket application?

Wicket separates authentication (who is this user) from authorization (what are they allowed to see or do), with the latter typically handled through the wicket-auth-roles module rather than scattering permission checks through page code.

  1. Implement a Session subclass that exposes the current user's roles, typically extending AuthenticatedWebSession.
  2. Register an authorization strategy in the Application's init(), commonly AnnotatedMountedRoleAuthorizationStrategy or the older RoleAuthorizationStrategy, which checks a component's required roles against the current session's roles before allowing it to render or be instantiated.
  3. Annotate pages or components with @AuthorizeInstantiation("ADMIN") (or the equivalent programmatic call) to restrict who can even construct that page, so an unauthorized user gets redirected before any of the page's content is built at all.
  4. Use finer-grained checks within a page for partial restrictions — hiding a specific button or panel for users lacking a role, rather than blocking the whole page.

Because the check happens at instantiation for page-level authorization, an unauthorized request never even runs the page's constructor logic, which is a meaningfully stronger guarantee than merely hiding a link in markup while leaving the underlying page reachable by URL.

What does the @AuthorizeInstantiation annotation actually prevent for an unauthorized user?
What must a Session subclass typically extend to expose the current user's roles for authorization checks?

More Related questions...

What is Apache Wicket? What is a Wicket Component? What is a Wicket Page? What is the wicket:id attribute? What is an IModel in Wicket? What are the types of built-in form components in Wicket? What is a Wicket Panel? What is a Wicket Fragment? What is the purpose of the WicketApplication class? What are the types of models Wicket provides out of the box? Define markup inheritance in Wicket? What is a bookmarkable page in Wicket? How do you create a simple Wicket Link component? What is the purpose of PageParameters? What is WicketTester? Why does Wicket avoid using JSP for markup? Why do we use LoadableDetachableModel instead of a plain field reference? How does Wicket manage component state across requests? What is the difference between a stateful and a stateless page in Wicket? When should you use a Panel instead of a Fragment? What is the difference between PropertyModel and CompoundPropertyModel? What happens when you call setResponsePage() inside a Wicket event handler? What is the difference between Wicket 9 and Wicket 10? Which is better for a new project in 2026: Wicket 9 or Wicket 10, and why? How can you optimize page load performance in a large Wicket application? How do you troubleshoot a WicketRuntimeException about a missing wicket:id? Explain the lifecycle of a Wicket request from URL to rendered page? Explain the execution flow of an AjaxLink click in Wicket? Explain the internal working of Wicket's component tree rendering? What is the difference between an AjaxLink and a Link in Wicket? Why should you avoid storing large objects directly as page fields? What is a Wicket Behavior? How does Wicket integrate with Spring for dependency injection? What is the difference between IValidator and form-level validation in Wicket? How does Wicket support internationalization (i18n)? Explain the internal working of Wicket's URL mounting? What is the difference between Wicket 8, 9, and 10 in terms of Java/Jakarta support? How do you enforce authorization/roles in a Wicket application? What is the role of the wicket-auth-roles module? How does Wicket handle recent security vulnerabilities like session fixation issues? Explain the sequence of events when a Wicket Form is submitted? What is the difference between onSubmit() and onError() in a Wicket Form? How do you configure detachable models to avoid memory leaks in the HttpSession? What is the difference between Wicket's component-oriented approach and Spring MVC's request-oriented approach? Explain how Wicket's PackageResourceGuard works and why CVE-2026-43646 mattered? How do you integrate WebSockets into a Wicket application? What is the difference between page storage strategies (in-memory vs disk-based) in Wicket? Explain the internal working of Wicket's markup inheritance resolution? What is the difference between Apache Wicket, Spring MVC, and JSF? Explain how Wicket's CryptoMapper protects bookmarkable page URLs from tampering?
Show more question and Answers...


Comments & Discussions