Modified jaas sample's LoginModule to prevent empty string username/password

This commit is contained in:
Rob Winch 2011-03-06 19:01:13 -06:00
parent 9e5d35235c
commit a50c9afbab
1 changed files with 3 additions and 0 deletions

View File

@ -71,6 +71,9 @@ public class UsernameEqualsPasswordLoginModule implements LoginModule {
if (username == null || !username.equals(password)) {
throw new LoginException("username is not equal to password");
}
if("".equals(username)) {
throw new LoginException("username cannot be empty string");
}
subject.getPrincipals().add(new UsernamePrincipal(username));
return true;