java - Spring security with different type of sessions -
i'm using spring security 3.1.4 , have following problem. in 1 web app have 2 types of users different custom "userdetails" instance. how differentiate between users in implementation of userdetailsservice.loaduserbyusername. can have 2 userdetailsserviceimpl , know when use each one?
well, suggest implement composite userdetailsservice
, perform loaduserbyusername
both db 1 one. , logical, first userdetailsserviceimpl
use should regular user
, tipical, count of admin user
less.
however design looks bad. better have separate hidden application admins , rid of little vulnerability when simple user might guess admin account.
Comments
Post a Comment