Thursday, May 21, 2009

Oracle Securing Web services

A web service can be secured at the transport level (eg https) or at the message level (WS-Security).

Setting https on Oc4j standalone
https:
http://technology.amis.nl/blog/268/quick-and-easy-ssl-in-oc4j-standalone
http://tugdualgrall.blogspot.com/2006/10/using-https-with-web-services.html
http://www.coderanch.com/t/224567/Web-Services/java/Connecting-HTTPS-webservice-through-oracle

Note that when setting default-web-site.xml and secure-web-site.xml make also sure to include shared="true" to the applications or web services that need to support https.



Finally when generating the keystore file and answering to the question what is your first and last name, put there the domain of the application server.

WS-Security:

http://www.oracle.com/technology/oramag/oracle/05-jan/o15web.html
http://www.oracle.com/technology/oramag/oracle/05-mar/o25web.html


Also when oc4j supports http and https and you want to be able to switch from http to https without restarting a session you will follow these instruction to update to orion-web.xml of the application:

Set the cookie domain if shared="true" and the default ports are not used. When the client interacts with a Web server over separate ports, the cookie believes that each separate port denotes a separate Web site. If you use the default ports of 80 for HTTP and 443 for HTTPS, the client recognizes these as two different ports of the same Web site and creates only a single cookie. However, if you use nondefault ports, the client does not recognize these ports as part of the same Web site and will create separate cookies for each port, unless you specify the cookie domain.
Cookie domains track the client's communication across multiple servers within a DNS domain. If you use nondefault ports for a shared environment with HTTP and HTTPS, set cookie-domain in the element in the orion-web.xml file for the application. The cookie-domain attribute contains the DNS domain with at least two components of the domain name provided:

The top down web service approach with Jdeveloper

Create xml schema and WSDL file and then generate the java classes from it.

http://www.oracle.com/technology/obe/obe1013jdev/10131/10131_wstopdown/wstopdown.htm

Tuesday, April 28, 2009

Convert Java Calendar to XMLGregorianCalendar

DatatypeFactory dtf = DatatypeFactory.newInstance();
XMLGregorianCalendar xgc = dtf.newXMLGregorianCalendar();
Calendar cal = Calendar.getInstance();
xgc.setYear(cal.get(Calendar.YEAR));
xgc.setDay(cal.get(Calendar.DAY_OF_MONTH));
xgc.setMonth(cal.get(Calendar.MONTH)+ 1);
xgc.setHour(cal.get(Calendar.HOUR_OF_DAY));
xgc.setMinute(cal.get(Calendar.MINUTE));
xgc.setSecond(cal.get(Calendar.SECOND));
xgc.setMillisecond(cal.get(Calendar.MILLISECOND));
// Calendar ZONE_OFFSET and DST_OFFSET fields are in milliseconds.
int offsetInMinutes = (cal.get(Calendar.ZONE_OFFSET) + cal.get(Calendar.DST_OFFSET)) / (60 * 1000);xgc.setTimezone(offsetInMinutes);



Simpler option:


GregorianCalendar gc = new GregorianCalendar();
DatatypeFactory dtf = DatatypeFactory.newInstance();
XMLGregorianCalendar xgc = dtf.newXMLGregorianCalendargc);
==================================================

Thursday, October 9, 2008

Stateful Oracle Web services using J2EE 1.4 with JAX-RPC


Stateful Oracle JAX-RPC web services are using specific HTTP headers from the client calling the Web Service that need to be setup if you want the Stateful web service to work.

Call the following set property in your client proxy:

setMaintainSession(true) otherwise the service will work as a stateless service. Also regular browsers don't support the http header extension.




Tuesday, September 30, 2008

Using Data Sources

These are links to data source topics.
Sun Datasource has been extended by Oracle as OracleDataSource();
The library to include in your project in Jdeveloper is named Oracle JDBC.

You can provide database credentials to a datasource or use JNDI (Lookup). The avantage of using JNDI is that no credentials are hardcoded.

DataSource LookUp using JNDI
http://www.java2s.com/Code/Java/Database-SQL-JDBC/TestDataSourceLookUp.htm

Using Datasource providing ODBC parameters:
http://www.java2s.com/Code/Java/Database-SQL-JDBC/OracleDataSourceDemo.htm

Using JDBC Data Sources with ADF Business Components
http://www.oracle.com/technology/products/jdev/howtos/10g/usingdatasources/using_datasources.html

Sun datasource overview why to use JNDI
http://java.sun.com/j2se/1.4.2/docs/guide/jdbc/getstart/datasource.html

Using OracleDataSource();
http://www.oracle.com/technology/products/oracle9i/daily/jun24.html




Monday, September 22, 2008

Enums, Iterator and enumerations in java

Creating Enums consist in creating classes behing the scene:
http://chaoticjava.com/posts/tricks-with-enums/

Iteror and Enumeration are interfaces
Enumeration are often considered faster than Iterators:
http://javabeanz.wordpress.com/2007/06/29/iterator-vs-enumeration/