<?xml version="1.0" encoding="UTF-8"?>

<beans:beans 
	xmlns="http://www.springframework.org/schema/security"
    xmlns:beans="http://www.springframework.org/schema/beans"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xmlns:jee="http://www.springframework.org/schema/jee"
    xsi:schemaLocation="
	    http://www.springframework.org/schema/security 
	    http://www.springframework.org/schema/security/spring-security-3.1.xsd        
	    http://www.springframework.org/schema/beans 
	    http://www.springframework.org/schema/beans/spring-beans-3.2.xsd">
   

	<http pattern="/statics/**" security="none"></http>
	<http auto-config='true' use-expressions="true">
	   
		<intercept-url pattern="/sign/**" access="permitAll" />
	    <intercept-url pattern="/monitoring/**" access="permitAll" />
	    <intercept-url pattern="/reload/monitoring/**" access="permitAll" />
	    	    
	    <intercept-url pattern="/ess/**" access="isAuthenticated()" />
	    
	    <intercept-url pattern="/admin/**" access="hasAnyRole('ROLE_05', 'ROLE_09')" />
	    <intercept-url pattern="/plant/**" access="hasAnyRole('ROLE_05', 'ROLE_09')" />
	    <intercept-url pattern="/pms/**" access="hasAnyRole('ROLE_05','ROLE_09')" />
	    <intercept-url pattern="/user/**" access="hasAnyRole('ROLE_05','ROLE_09')" />
	    <intercept-url pattern="/client/**" access="hasAnyRole('ROLE_05','ROLE_09')" />
	    <intercept-url pattern="/kesco/**" access="hasAnyRole('ROLE_05','ROLE_09')" />
	    <intercept-url pattern="/cs/**" access="hasAnyRole('ROLE_05', 'ROLE_09')" />
	    <intercept-url pattern="/report/**" access="hasAnyRole('ROLE_05', 'ROLE_09')" />
	    <intercept-url pattern="/sms/**" access="hasAnyRole('ROLE_05', 'ROLE_09')" />
	    
	    <form-login login-page="/sign/login.co"
	                username-parameter="userId"
	                password-parameter="userPwd"    
	                login-processing-url="/sign/loginProcess.co"
	                default-target-url="/sign/loginSuccess.co"
	                always-use-default-target='false'	   
	                authentication-success-handler-ref="userAuthSuccHandler" 
	                authentication-failure-url="/sign/login.co?error"
		/>
		
		<session-management>
			<concurrency-control max-sessions="2" expired-url="/sign/loginDuplicate.co"/>
	    </session-management>
	</http>


 	<beans:bean id="userAuthSuccHandler" class="com.elt.ems.security.UserAuthenticationSuccessHandler" > 		
 		<beans:constructor-arg name="authService" ref="userAuthService" />
	</beans:bean>	
	
 	<beans:bean id="userAuthenticationProvider" class="com.elt.ems.security.UserAuthenticationProvider" >
		<beans:constructor-arg name="authService" ref="userAuthService" />
	</beans:bean>	 
 	
	<beans:bean id="userAuthService" class="com.elt.ems.security.UserAuthenticationService">
		<beans:constructor-arg name="sqlSession" ref="sqlSession" />
	</beans:bean>	
	 	
	<authentication-manager>
		<authentication-provider ref="userAuthenticationProvider"/>
		<authentication-provider user-service-ref="userAuthService" /> 
	</authentication-manager>


</beans:beans>

<!--  

   

	
	

-->

<!-- 

		<authentication-manager>
			<authentication-provider user-service-ref="userService"/>
			<authentication-provider user-service-ref="memberService"/>
		</authentication-manager>	

		<beans:bean id="memberService" class="com.company.wmos.auth.MemberService" />
-->


