Java / Servlet Interview Questions
List a few annotations relevant to container security.
The @ServletSecurity annotation provides an alternative mechanism for defining access control constraints for the whole servlet. These annotations provide an alternative mechanism for specifying security constraints declaratively by
The @DeclareRoles annotation is used by application to declare security roles. It can be specified on a class. The value of the DeclareRoles annotation is a list of security role names.
The @DenyAll annotation specifies that no security roles are allowed to invoke the specified method(s) - i.e that the methods are to be excluded from execution in the J2EE container.
The @PermitAll annotation specifies that all security roles are allowed to invoke the specified method(s) i.e that the specified method(s) are "unchecked". It can be specified on a class or on methods. Specifying it in the class means that it applies to all methods of the class. If specified at the method level, it only affects that method.
The @RolesAllowed annotation specifies the security roles permitted to access methods in an application. This annotation can be specified on a class or on one or more methods. When specified at the class level, the annotation applies to all methods in the class. When specified on a method, the annotation applies to that method only and overrides any values specified at the class level.
The @RunAs annotation is equivalent to the <run-as> element in the deployment descriptor and allows developers to run code under the specified role.
More Related questions...