<?xml version="1.0" encoding="UTF-8"?>
<beans xmlns="http://www.springframework.org/schema/beans"
	xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:aop="http://www.springframework.org/schema/aop"
	xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd
       http://www.springframework.org/schema/aop http://www.springframework.org/schema/aop/spring-aop.xsd">

	<!-- ======================== FILTER CHAIN ======================= -->
	<bean id="filterChainProxy" class="net.sf.acegisecurity.util.FilterChainProxy">
		<property name="filterInvocationDefinitionSource">
		<value>
			<![CDATA[
			CONVERT_URL_TO_LOWERCASE_BEFORE_COMPARISON
			PATTERN_TYPE_APACHE_ANT
			/ws-iparapheur**=	httpSessionContextIntegrationFilter,x509AndBasicAuthenticationProcessingFilter
			]]>
		</value>
		</property>
	</bean>
<!--			/ws-iparapheur**=	channelProcessingFilter,httpSessionContextIntegrationFilter,x509AndBasicAuthenticationProcessingFilter,securityEnforcementFilter,filterInvocationInterceptor
-->

	<!-- ======================== AUTHENTICATION ======================= -->
<!--  STV	<bean id="authenticationManager" class="net.sf.acegisecurity.providers.ProviderManager">
		<property name="providers">
			<list>
				<ref local="daoAuthenticationProvider" />
			</list>
		</property>
	</bean> -->
	<!-- N'est plus utilisé
	<bean id="inMemoryDaoImpl"	class="net.sf.acegisecurity.providers.dao.memory.InMemoryDaoImpl">
		<property name="userMap">
			<value>
				<![CDATA[
					prototype-client.ws_user=password,ROLE_WSUSER
				]]>
			</value>
		</property>
	</bean>
	<bean id="daoAuthenticationProvider" class="net.sf.acegisecurity.providers.dao.DaoAuthenticationProvider">
		<property name="authenticationDao">
			<ref local="repositoryAuthenticationDao" />
		</property>
	</bean> -->

            <bean id="authenticationManager" class="net.sf.acegisecurity.providers.ProviderManager">
                <property name="providers">
                    <list>
                        <ref bean="authenticatedAuthenticationPassthroughProvider" />
                        <ref bean="daoAuthenticationProvider" />
                    </list>
                </property>
            </bean>
            <bean id="daoAuthenticationProvider" class="net.sf.acegisecurity.providers.dao.DaoAuthenticationProvider">
                <property name="authenticationDao">
                    <ref bean="authenticationDao" />
                </property>
                <property name="saltSource">
                    <ref bean="authenticationDao" />
                </property>
                <property name="passwordEncoder">
                    <ref bean="passwordEncoder" />
                </property>
            </bean>

	<bean id="basicProcessingFilterEntryPoint" class="net.sf.acegisecurity.ui.basicauth.BasicProcessingFilterEntryPoint">
		<property name="realmName">
			<value>Contacts Realm</value>
		</property>
	</bean>

	<bean id="x509AndBasicAuthenticationProcessingFilter" class="org.adullact.iparapheur.ws.security.X509AndBasicAuthenticationProcessingFilter">
		<property name="authenticationManager">
			<ref bean="authenticationManager" />	<!--ref local="authenticationManager" /-->
		</property>
		<property name="authenticationComponent">
			<ref bean="authenticationComponent" />
		</property>
		<property name="transactionService">
			<ref bean="transactionService" />
		</property>
		<property name="basicAuthenticationEntryPoint">
			<ref local="basicProcessingFilterEntryPoint" />
		</property>
		<property name="dealWithCertificate">
			<value>false</value>
		</property>
		<property name="x509SubjectDNRegex">
			<value>CN=(.*?),</value>
		</property>
		<property name="tokenSeparator">
			<value>.</value>
		</property>
	</bean>
<!--	<bean id="exceptionTranslationFilter" class="net.sf.acegisecurity.ui.ExceptionTranslationFilter">
		<property name="authenticationEntryPoint">
			<ref local="basicProcessingFilterEntryPoint" />
		</property>
	</bean> -->

	<!-- ======================== COMMON ======================= -->
	<bean id="httpSessionContextIntegrationFilter" class="net.sf.acegisecurity.context.HttpSessionContextIntegrationFilter">
		<property name="context" value="net.sf.acegisecurity.context.security.SecureContextImpl" />
	</bean>
	<bean id="roleVoter" class="net.sf.acegisecurity.vote.RoleVoter" />

	<bean id="channelProcessingFilter" class="net.sf.acegisecurity.securechannel.ChannelProcessingFilter">
		<property name="channelDecisionManager">
			<ref local="channelDecisionManager" />
		</property>
		<property name="filterInvocationDefinitionSource">
			<value>
				<![CDATA[
					CONVERT_URL_TO_LOWERCASE_BEFORE_COMPARISON
					\A/ws-iparapheur.*\Z=REQUIRES_SECURE_CHANNEL
				]]>
			</value>
		</property>
	</bean>
    <!-- BASIC Regular Expression Syntax (for beginners):
         \A means the start of the string (ie the beginning of the URL)
         \Z means the end of the string (ie the end of the URL)
         .  means any single character
         *  means null or any number of repetitions of the last expression (so .* means zero or more characters)

         Some examples:

         Expression:   \A/my/directory/.*\Z
         Would match:    /my/directory/
                         /my/directory/hello.html

         Expression:   \A/.*\Z
         Would match:    /hello.html
                         /

         Expression:   \A/.*/secret.html\Z
         Would match:    /some/directory/secret.html
                         /another/secret.html
         Not match:      /anothersecret.html (missing required /)
    -->

	<bean id="channelDecisionManager" class="net.sf.acegisecurity.securechannel.ChannelDecisionManagerImpl">
		<property name="channelProcessors">
			<list>
				<ref local="secureChannelProcessor" />
				<ref local="insecureChannelProcessor" />
			</list>
		</property>
	</bean>
	<bean id="secureChannelProcessor" class="net.sf.acegisecurity.securechannel.SecureChannelProcessor" />
	<bean id="insecureChannelProcessor" class="net.sf.acegisecurity.securechannel.InsecureChannelProcessor" />

	<bean id="httpRequestAccessDecisionManager" class="net.sf.acegisecurity.vote.AffirmativeBased">
		<property name="allowIfAllAbstainDecisions">
			<value>false</value>
		</property>
		<property name="decisionVoters">
			<list>
				<ref bean="roleVoter" />
			</list>
		</property>
	</bean>

	<!--	Adaptation pour ACEGI 0.8.2: le filtre d'interception est encapsulé dans un filtre de sécurité	-->
	<bean id="securityEnforcementFilter" class="net.sf.acegisecurity.intercept.web.SecurityEnforcementFilter">
		<property name="filterSecurityInterceptor" ref="filterInvocationInterceptor" />
		<property name="authenticationEntryPoint" ref="basicProcessingFilterEntryPoint" />
	</bean>

	<bean id="filterInvocationInterceptor" class="net.sf.acegisecurity.intercept.web.FilterSecurityInterceptor">
		<property name="authenticationManager">
			<ref bean="authenticationManager" />
		</property>
		<property name="accessDecisionManager">
			<ref local="httpRequestAccessDecisionManager" />
		</property>
		<property name="objectDefinitionSource">
			<value>
				<![CDATA[
					CONVERT_URL_TO_LOWERCASE_BEFORE_COMPARISON
					\A/ws-iparapheur.*\Z=ROLE_AUTHENTICATED
				]]>
			</value>
		</property>
	</bean>
<!-- 					\A/ws-iparapheur.*\Z=ROLE_WSUSER		-->
<!--
	<bean id="autoProxyCreator" class="org.springframework.aop.framework.autoproxy.BeanNameAutoProxyCreator">
		<property name="interceptorNames">
			<list>
				<value><![CDATA[servicesSecurityInterceptor]]></value>
			</list>
		</property>
		<property name="beanNames">
			<list>
				<value>businessService</value>
			</list>
		</property>
	</bean>
	<bean id="servicesSecurityInterceptor" class="net.sf.acegisecurity.intercept.method.aopalliance.MethodSecurityInterceptor">
		<property name="validateConfigAttributes">
			<value>true</value>
		</property>
		<property name="authenticationManager">
			<ref bean="authenticationManager" />
		</property>
		<property name="accessDecisionManager">
			<ref bean="httpRequestAccessDecisionManager" />
		</property>
		<property name="objectDefinitionSource">
			<value> <![CDATA[
				fr.bl.services.business.IBusinessService.sayHello=ROLE_WSUSER
				fr.bl.services.business.IBusinessService.doBusiness=ROLE_SUPERWSUSER
				]]>
			</value>
		</property>
	</bean>	-->

</beans>
