【发布时间】:2015-07-11 18:11:00
【问题描述】:
我有以下代码更改。
- @PreAuthorize("isAuthenticated()")
+ @PreAuthorize("hasPermission(#dto.perusteId, 'peruste', 'LUKU')")
public void setStarted(DokumenttiDto dto);
根据 spring 文档,身份验证对象不应为 null。在这里,开发人员删除了 authentication 检查并放置了 hasPermission 检查。那么如果身份验证对象为 null ,hasPermission 方法会返回 false 吗?身份验证对象将由 spring 安全框架自动提供。这可以被视为重构更改吗?两项检查(身份验证+权限检查)合二为一(权限检查)!我不认为 hasPermission 方法实现正在对身份验证对象进行任何检查。(https://github.com/Opetushallitus/eperusteet/blob/cd9eff86bdda5dd91072354392dedbe0783c9ddf/eperusteet/eperusteet-service/src/main/java/fi/vm/sade/eperusteet/service/security/PermissionEvaluator.java)
这里是代码更改链接:https://github.com/Opetushallitus/eperusteet/commit/e8459
Method Detail
hasPermission
public boolean hasPermission(Authentication authentication,
Object domainObject,
Object permission)
Determines whether the user has the given permission(s) on the domain object using the ACL configuration. If the domain object is null, returns false (this can always be overridden using a null check in the expression itself).
Specified by:
hasPermission in interface PermissionEvaluator
Parameters:
authentication - represents the user in question. Should not be null.
domainObject - the domain object for which permissions should be checked. May be null in which case implementations should return false, as the null condition can be checked explicitly in the expression.
permission - a representation of the permission object as supplied by the expression system. Not null.
【问题讨论】:
标签: java spring authentication spring-security spring-annotations