<?xml version="1.0"?>
<!DOCTYPE web-app PUBLIC 
'-//Sun Microsystems, Inc.//DTD Web Application 2.3//EN' 
'http://java.sun.com/dtd/web-app_2_3.dtd'>
    
<web-app>
  <security-constraint>
    <web-resource-collection>
      <web-resource-name>AdminPages</web-resource-name>
      <description>
        These pages are only accessible by authorised administrators.
      </description>
      <url-pattern>/*</url-pattern>
      <http-method>GET</http-method>
      <http-method>POST</http-method>
    </web-resource-collection>
    <auth-constraint>
      <description>
        These are the roles who have access
      </description>
        <role-name>
          admin
        </role-name>
    </auth-constraint>
    <user-data-constraint>
      <description>
        This is how the user data must be transmitted
      </description>
      <transport-guarantee>NONE</transport-guarantee>
    </user-data-constraint>
  </security-constraint>
  <login-config>
    <auth-method>basic</auth-method>
    <!--
    <form-login-config>
      <form-login-page>/login.jsp</form-login-page>
      <form-error-page>/fail_login.html</form-error-page>
    </form-login-config>
    -->
  </login-config>
  <security-role>
    <description>
      An administrator
    </description>
    <role-name>
      admin
    </role-name>
  </security-role>
</web-app>

