Organizational Research By

Surprising Reserch Topic

session tracking using j2ee

session tracking using j2ee  using -'jsp,session,java-ee,servlets'

I'm trying to implement session tracking on my website. Basically I want the users to be able to login in my website using their username and their password, pass throw my website pages (only available for logged users) and then logout.
Currently I'm thinking about what is the right architecture to accomplish this. So, is it right to do it like this: use a servlet which validates whether the user is logged or not or if this one is doing a login using a httpSession object (kinda like this example here: In case of a login attemp the servlet validates the username and password by calling a stateless session bean (which validates the username and password based on my database).

Also everytime the user wants to "travel" to another page on my website that is only visible to logged users, the request must go to the servlet to validate whether the user is logged or not and then retrieve the new page.

Is this the right way to do it? If not how can I accomplish this?

Thanks a lot.

asked Oct 19, 2015 by sandeep bhadauria
0 votes

Related Hot Questions

3 Answers

0 votes

I am confused with term session tracking, but I understand that you want to allow users to access protected resources.

What you need is to define roles, authentication provider and mapping for secured resources. Then you can combine it in web.xml:


See for details. This is JEE standard way.

answered Oct 19, 2015 by patelnikul321
0 votes

You can use a servlet to login to your application.

But you need a filter to restrict access to secured pages.

Every request must pass through that filter.

answered Oct 19, 2015 by kinnari
0 votes

You can use Spring Security. It has all the features you require. Spring Security provides comprehensive security services for J2EE-based enterprise software applications.

The framework will authenticate and authorize the user based on the configuration done in the framework. And will automatically save the user state in the session. You don't have to explicitly deal with sessions.

answered Oct 19, 2015 by dahiyabecomp