소스 파일 최초 업로드
This commit is contained in:
71
tomcat/webapps.dist/host-manager/WEB-INF/jsp/401.jsp
Normal file
71
tomcat/webapps.dist/host-manager/WEB-INF/jsp/401.jsp
Normal file
@@ -0,0 +1,71 @@
|
||||
<%--
|
||||
Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
contributor license agreements. See the NOTICE file distributed with
|
||||
this work for additional information regarding copyright ownership.
|
||||
The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
(the "License"); you may not use this file except in compliance with
|
||||
the License. You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
--%>
|
||||
<%@ page session="false" trimDirectiveWhitespaces="true" %>
|
||||
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
|
||||
<html>
|
||||
<head>
|
||||
<title>401 Unauthorized</title>
|
||||
<style type="text/css">
|
||||
<!--
|
||||
BODY {font-family:Tahoma,Arial,sans-serif;color:black;background-color:white;font-size:12px;}
|
||||
H1 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:22px;}
|
||||
PRE, TT {border: 1px dotted #525D76}
|
||||
A {color : black;}A.name {color : black;}
|
||||
-->
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<h1>401 Unauthorized</h1>
|
||||
<p>
|
||||
You are not authorized to view this page. If you have not changed
|
||||
any configuration files, please examine the file
|
||||
<tt>conf/tomcat-users.xml</tt> in your installation. That
|
||||
file must contain the credentials to let you use this webapp.
|
||||
</p>
|
||||
<p>
|
||||
For example, to add the <tt>admin-gui</tt> role to a user named
|
||||
<tt>tomcat</tt> with a password of <tt>s3cret</tt>, add the following to the
|
||||
config file listed above.
|
||||
</p>
|
||||
<pre>
|
||||
<role rolename="admin-gui"/>
|
||||
<user username="tomcat" password="s3cret" roles="admin-gui"/>
|
||||
</pre>
|
||||
<p>
|
||||
Note that for Tomcat 7 onwards, the roles required to use the host manager
|
||||
application were changed from the single <tt>admin</tt> role to the
|
||||
following two roles. You will need to assign the role(s) required for
|
||||
the functionality you wish to access.
|
||||
</p>
|
||||
<ul>
|
||||
<li><tt>admin-gui</tt> - allows access to the HTML GUI</li>
|
||||
<li><tt>admin-script</tt> - allows access to the text interface</li>
|
||||
</ul>
|
||||
<p>
|
||||
The HTML interface is protected against CSRF but the text interface is not.
|
||||
To maintain the CSRF protection:
|
||||
</p>
|
||||
<ul>
|
||||
<li>Users with the <tt>admin-gui</tt> role should not be granted the
|
||||
<tt>admin-script</tt> role.</li>
|
||||
<li>If the text interface is accessed through a browser (e.g. for testing
|
||||
since this interface is intended for tools not humans) then the browser
|
||||
must be closed afterwards to terminate the session.</li>
|
||||
</ul>
|
||||
</body>
|
||||
|
||||
</html>
|
||||
90
tomcat/webapps.dist/host-manager/WEB-INF/jsp/403.jsp
Normal file
90
tomcat/webapps.dist/host-manager/WEB-INF/jsp/403.jsp
Normal file
@@ -0,0 +1,90 @@
|
||||
<%--
|
||||
Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
contributor license agreements. See the NOTICE file distributed with
|
||||
this work for additional information regarding copyright ownership.
|
||||
The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
(the "License"); you may not use this file except in compliance with
|
||||
the License. You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
--%>
|
||||
<%@ page session="false" trimDirectiveWhitespaces="true" %>
|
||||
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
|
||||
<html>
|
||||
<head>
|
||||
<title>403 Access Denied</title>
|
||||
<style type="text/css">
|
||||
<!--
|
||||
BODY {font-family:Tahoma,Arial,sans-serif;color:black;background-color:white;font-size:12px;}
|
||||
H1 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:22px;}
|
||||
PRE, TT {border: 1px dotted #525D76}
|
||||
A {color : black;}A.name {color : black;}
|
||||
-->
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<h1>403 Access Denied</h1>
|
||||
<p>
|
||||
You are not authorized to view this page.
|
||||
</p>
|
||||
<p>
|
||||
By default the Host Manager is only accessible from a browser running on the
|
||||
same machine as Tomcat. If you wish to modify this restriction, you'll need
|
||||
to edit the Host Manager's <tt>context.xml</tt> file.
|
||||
</p>
|
||||
<p>
|
||||
If you have already configured the Host Manager application to allow access
|
||||
and you have used your browsers back button, used a saved book-mark or
|
||||
similar then you may have triggered the cross-site request forgery (CSRF)
|
||||
protection that has been enabled for the HTML interface of the Host Manager
|
||||
application. You will need to reset this protection by returning to the
|
||||
<a href="<%=request.getContextPath()%>/html">main Host Manager page</a>.
|
||||
Once you return to this page, you will be able to continue using the Host
|
||||
Manager application's HTML interface normally. If you continue to see this
|
||||
access denied message, check that you have the necessary permissions to
|
||||
access this application.
|
||||
</p>
|
||||
<p> If you have not changed
|
||||
any configuration files, please examine the file
|
||||
<tt>conf/tomcat-users.xml</tt> in your installation. That
|
||||
file must contain the credentials to let you use this webapp.
|
||||
</p>
|
||||
<p>
|
||||
For example, to add the <tt>admin-gui</tt> role to a user named
|
||||
<tt>tomcat</tt> with a password of <tt>s3cret</tt>, add the following to the
|
||||
config file listed above.
|
||||
</p>
|
||||
<pre>
|
||||
<role rolename="admin-gui"/>
|
||||
<user username="tomcat" password="s3cret" roles="admin-gui"/>
|
||||
</pre>
|
||||
<p>
|
||||
Note that for Tomcat 7 onwards, the roles required to use the host manager
|
||||
application were changed from the single <tt>admin</tt> role to the
|
||||
following two roles. You will need to assign the role(s) required for
|
||||
the functionality you wish to access.
|
||||
</p>
|
||||
<ul>
|
||||
<li><tt>admin-gui</tt> - allows access to the HTML GUI</li>
|
||||
<li><tt>admin-script</tt> - allows access to the text interface</li>
|
||||
</ul>
|
||||
<p>
|
||||
The HTML interface is protected against CSRF but the text interface is not.
|
||||
To maintain the CSRF protection:
|
||||
</p>
|
||||
<ul>
|
||||
<li>Users with the <tt>admin-gui</tt> role should not be granted the
|
||||
<tt>admin-script</tt> role.</li>
|
||||
<li>If the text interface is accessed through a browser (e.g. for testing
|
||||
since this interface is intended for tools not humans) then the browser
|
||||
must be closed afterwards to terminate the session.</li>
|
||||
</ul>
|
||||
</body>
|
||||
|
||||
</html>
|
||||
62
tomcat/webapps.dist/host-manager/WEB-INF/jsp/404.jsp
Normal file
62
tomcat/webapps.dist/host-manager/WEB-INF/jsp/404.jsp
Normal file
@@ -0,0 +1,62 @@
|
||||
<%--
|
||||
Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
contributor license agreements. See the NOTICE file distributed with
|
||||
this work for additional information regarding copyright ownership.
|
||||
The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
(the "License"); you may not use this file except in compliance with
|
||||
the License. You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
--%>
|
||||
<%@ page import="org.apache.tomcat.util.security.Escape" session="false"
|
||||
trimDirectiveWhitespaces="true" %>
|
||||
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
|
||||
<html>
|
||||
<head>
|
||||
<title>404 Not found</title>
|
||||
<style type="text/css">
|
||||
<!--
|
||||
BODY {font-family:Tahoma,Arial,sans-serif;color:black;background-color:white;font-size:12px;}
|
||||
H1 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:22px;}
|
||||
PRE, TT {border: 1px dotted #525D76}
|
||||
A {color : black;}A.name {color : black;}
|
||||
-->
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<h1>404 Not found</h1>
|
||||
<p>
|
||||
The page you tried to access
|
||||
(<%=Escape.htmlElementContent((String) request.getAttribute(
|
||||
"javax.servlet.error.request_uri"))%>)
|
||||
does not exist.
|
||||
</p>
|
||||
<p>
|
||||
The Host Manager application has been re-structured for Tomcat 7 onwards and
|
||||
some URLs have changed. All URLs used to access the Manager application
|
||||
should now start with one of the following options:
|
||||
</p>
|
||||
<ul>
|
||||
<li><%=request.getContextPath()%>/html for the HTML GUI</li>
|
||||
<li><%=request.getContextPath()%>/text for the text interface</li>
|
||||
</ul>
|
||||
<p>
|
||||
Note that the URL for the text interface has changed from
|
||||
"<%=request.getContextPath()%>" to
|
||||
"<%=request.getContextPath()%>/text".
|
||||
</p>
|
||||
<p>
|
||||
You probably need to adjust the URL you are using to access the Host Manager
|
||||
application. However, there is always a chance you have found a bug in the
|
||||
Host Manager application. If you are sure you have found a bug, and that the
|
||||
bug has not already been reported, please report it to the Apache Tomcat
|
||||
team.
|
||||
</p>
|
||||
</body>
|
||||
</html>
|
||||
30
tomcat/webapps.dist/host-manager/WEB-INF/manager.xml
Normal file
30
tomcat/webapps.dist/host-manager/WEB-INF/manager.xml
Normal file
@@ -0,0 +1,30 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!--
|
||||
Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
contributor license agreements. See the NOTICE file distributed with
|
||||
this work for additional information regarding copyright ownership.
|
||||
The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
(the "License"); you may not use this file except in compliance with
|
||||
the License. You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
-->
|
||||
<!--
|
||||
|
||||
Context configuration file for the Tomcat Manager Web App
|
||||
|
||||
-->
|
||||
<Context docBase="${catalina.home}/webapps/manager"
|
||||
privileged="true" antiResourceLocking="false" >
|
||||
<CookieProcessor className="org.apache.tomcat.util.http.Rfc6265CookieProcessor"
|
||||
sameSiteCookies="strict" />
|
||||
<Valve className="org.apache.catalina.valves.RemoteAddrValve"
|
||||
allow="127\.\d+\.\d+\.\d+|::1|0:0:0:0:0:0:0:1" />
|
||||
<Manager sessionAttributeValueClassNameFilter="java\.lang\.(?:Boolean|Integer|Long|Number|String)|org\.apache\.catalina\.filters\.CsrfPreventionFilter\$LruCache(?:\$1)?|java\.util\.(?:Linked)?HashMap"/>
|
||||
</Context>
|
||||
148
tomcat/webapps.dist/host-manager/WEB-INF/web.xml
Normal file
148
tomcat/webapps.dist/host-manager/WEB-INF/web.xml
Normal file
@@ -0,0 +1,148 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!--
|
||||
Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
contributor license agreements. See the NOTICE file distributed with
|
||||
this work for additional information regarding copyright ownership.
|
||||
The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
(the "License"); you may not use this file except in compliance with
|
||||
the License. You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
-->
|
||||
<web-app xmlns="http://xmlns.jcp.org/xml/ns/javaee"
|
||||
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
||||
xsi:schemaLocation="http://xmlns.jcp.org/xml/ns/javaee
|
||||
http://xmlns.jcp.org/xml/ns/javaee/web-app_4_0.xsd"
|
||||
version="4.0"
|
||||
metadata-complete="true">
|
||||
|
||||
<display-name>Tomcat Host Manager Application</display-name>
|
||||
<description>
|
||||
A scriptable host management web application for the Tomcat Web Server;
|
||||
Manager lets you view, create and remove virtual hosts.
|
||||
</description>
|
||||
|
||||
<request-character-encoding>UTF-8</request-character-encoding>
|
||||
|
||||
<servlet>
|
||||
<servlet-name>HostManager</servlet-name>
|
||||
<servlet-class>org.apache.catalina.manager.host.HostManagerServlet</servlet-class>
|
||||
<init-param>
|
||||
<param-name>debug</param-name>
|
||||
<param-value>2</param-value>
|
||||
</init-param>
|
||||
</servlet>
|
||||
<servlet>
|
||||
<servlet-name>HTMLHostManager</servlet-name>
|
||||
<servlet-class>org.apache.catalina.manager.host.HTMLHostManagerServlet</servlet-class>
|
||||
<init-param>
|
||||
<param-name>debug</param-name>
|
||||
<param-value>2</param-value>
|
||||
</init-param>
|
||||
</servlet>
|
||||
|
||||
<filter>
|
||||
<filter-name>CSRF</filter-name>
|
||||
<filter-class>org.apache.catalina.filters.CsrfPreventionFilter</filter-class>
|
||||
<init-param>
|
||||
<param-name>entryPoints</param-name>
|
||||
<param-value>/html,/html/,/html/list,/index.jsp</param-value>
|
||||
</init-param>
|
||||
</filter>
|
||||
|
||||
<!-- Configured to set X-FRAME-OPTIONS. Disable HSTS in case it interferes -->
|
||||
<!-- with an existing setting. Keep X-Content-Type-Options and -->
|
||||
<!-- X-XSS-Protection as they are page specific. -->
|
||||
<filter>
|
||||
<filter-name>HTTP header security filter</filter-name>
|
||||
<filter-class>org.apache.catalina.filters.HttpHeaderSecurityFilter</filter-class>
|
||||
<init-param>
|
||||
<param-name>hstsEnabled</param-name>
|
||||
<param-value>false</param-value>
|
||||
</init-param>
|
||||
</filter>
|
||||
|
||||
<filter-mapping>
|
||||
<filter-name>CSRF</filter-name>
|
||||
<servlet-name>HTMLHostManager</servlet-name>
|
||||
</filter-mapping>
|
||||
|
||||
<filter-mapping>
|
||||
<filter-name>HTTP header security filter</filter-name>
|
||||
<url-pattern>/*</url-pattern>
|
||||
</filter-mapping>
|
||||
|
||||
<!-- Define the Manager Servlet Mapping -->
|
||||
<servlet-mapping>
|
||||
<servlet-name>HostManager</servlet-name>
|
||||
<url-pattern>/text/*</url-pattern>
|
||||
</servlet-mapping>
|
||||
<servlet-mapping>
|
||||
<servlet-name>HTMLHostManager</servlet-name>
|
||||
<url-pattern>/html/*</url-pattern>
|
||||
</servlet-mapping>
|
||||
|
||||
<!-- Define a Security Constraint on this Application -->
|
||||
<security-constraint>
|
||||
<web-resource-collection>
|
||||
<web-resource-name>HostManager commands</web-resource-name>
|
||||
<url-pattern>/text/*</url-pattern>
|
||||
</web-resource-collection>
|
||||
<auth-constraint>
|
||||
<!-- NOTE: This role is not present in the default users file -->
|
||||
<role-name>admin-script</role-name>
|
||||
</auth-constraint>
|
||||
</security-constraint>
|
||||
<security-constraint>
|
||||
<web-resource-collection>
|
||||
<web-resource-name>HTMLHostManager commands</web-resource-name>
|
||||
<url-pattern>/html/*</url-pattern>
|
||||
</web-resource-collection>
|
||||
<auth-constraint>
|
||||
<!-- NOTE: This role is not present in the default users file -->
|
||||
<role-name>admin-gui</role-name>
|
||||
</auth-constraint>
|
||||
</security-constraint>
|
||||
|
||||
<!-- Define the Login Configuration for this Application -->
|
||||
<login-config>
|
||||
<auth-method>BASIC</auth-method>
|
||||
<realm-name>Tomcat Host Manager Application</realm-name>
|
||||
</login-config>
|
||||
|
||||
<!-- Security roles referenced by this web application -->
|
||||
<security-role>
|
||||
<description>
|
||||
The role that is required to log in to the Host Manager Application HTML
|
||||
interface
|
||||
</description>
|
||||
<role-name>admin-gui</role-name>
|
||||
</security-role>
|
||||
<security-role>
|
||||
<description>
|
||||
The role that is required to log in to the Host Manager Application text
|
||||
interface
|
||||
</description>
|
||||
<role-name>admin-script</role-name>
|
||||
</security-role>
|
||||
|
||||
<error-page>
|
||||
<error-code>401</error-code>
|
||||
<location>/WEB-INF/jsp/401.jsp</location>
|
||||
</error-page>
|
||||
<error-page>
|
||||
<error-code>403</error-code>
|
||||
<location>/WEB-INF/jsp/403.jsp</location>
|
||||
</error-page>
|
||||
<error-page>
|
||||
<error-code>404</error-code>
|
||||
<location>/WEB-INF/jsp/404.jsp</location>
|
||||
</error-page>
|
||||
|
||||
</web-app>
|
||||
Reference in New Issue
Block a user