【问题标题】:Does hasPermission return false if the authentication object is null如果身份验证对象为空,hasPermission 是否返回 false
【发布时间】:2015-07-11 18:11:00
【问题描述】:

我有以下代码更改。

-    @PreAuthorize("isAuthenticated()")
+    @PreAuthorize("hasPermission(#dto.perusteId, 'peruste', 'LUKU')")
     public void setStarted(DokumenttiDto dto);

根据 spring 文档,身份验证对象不应为 null。在这里,开发人员删除了 authentication 检查并放置了 hasPermission 检查。那么如果身份验证对象为 null ,hasPermission 方法会返回 false 吗?身份验证对象将由 spring 安全框架自动提供。这可以被视为重构更改吗?两项检查(身份验证+权限检查)合二为一(权限检查)!我不认为 hasPermission 方法实现正在对身份验证对象进行任何检查。(https://github.com/Opetushallitus/eperusteet/blob/cd9eff86bdda5dd91072354392dedbe0783c9ddf/eperusteet/eperusteet-service/src/main/java/fi/vm/sade/eperusteet/service/security/PermissionEvaluator.java)

这里是代码更改链接:https://github.com/Opetushallitus/eperusteet/commit/e8459

Method Detail

hasPermission
public boolean hasPermission(Authentication authentication,
                    Object domainObject,
                    Object permission)
Determines whether the user has the given permission(s) on the domain object using the ACL configuration. If the domain object is null, returns false (this can always be overridden using a null check in the expression itself).
Specified by:
hasPermission in interface PermissionEvaluator
Parameters:
authentication - represents the user in question. Should not be null.
domainObject - the domain object for which permissions should be checked. May be null in which case implementations should return false, as the null condition can be checked explicitly in the expression.
permission - a representation of the permission object as supplied by the expression system. Not null.

【问题讨论】:

    标签: java spring authentication spring-security spring-annotations


    【解决方案1】:

    我希望它的作用是

    它返回一个权限对象,实际上是用户拥有的所有权限的数组/列表

    如果您的用户没有任何角色,则返回一个空列表并将其添加到身份验证对象中

    例如

    Authentication object when 
    
    User with roles
    permissions = ['admin, 'user', 'moderator'];
    User with no roles
    permissions = []
    

    【讨论】:

    • 认证对象为空时会发生什么?
    • 您在 spring security 中有一个委托过滤器,它创建一个 Authentication 对象并将其发送到 AuthenticationManger 然后 AuthenticationProvider 以验证访问资源的用户。如果用户未通过身份验证,它将采取默认操作(或您声明它要执行的操作),否则它只会从 SpringSecutity 上下文中获取用户并让用户访问资源
    【解决方案2】:

    hasPermission 函数(如果正确连接到安全表达式评估器)实际上只是将authentication 令牌传递给PermissionManager.hasPermission。如果您查看代码,大多数复杂的 if 语句最终都会调用 hasAnyRole,当 authentication 对象为空时返回 false。

    然而,这整个班级太混乱了,我不能说它比现实中的随机数生成器更好。

    【讨论】:

      猜你喜欢
      • 2018-09-07
      • 1970-01-01
      • 2017-06-12
      • 2021-12-27
      • 1970-01-01
      • 2020-12-03
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多