> We are implementing customize Tomcat Realm, but not sure from which
> place to get browser sent information.
[quoted text clipped - 3 lines]
>
> Any suggestion are highly welcome.
As I remember it, the only bits of information that you can get passed into
a Realm are username and password. There's a pretty well-defined way to
fetch these, though I don't remember the details right now. You don't get an
HttpServletRequest, that's for sure. That's because it's up to the servlet
container to fetch the username and password for the Realm implementation;
there are a variety of ways for it to do that.
A Realm's role in life is to take the username/password credentials the
container passes to it and create Principle objects -- if the credentials
are valid -- reflecting the identified user and its roles.
-- Adam MAass