【发布时间】:2019-09-18 16:55:48
【问题描述】:
我使用几个 @PreAuthorize-base 注释来保护我的 REST API 方法。
@Target(ElementType.METHOD)
@Retention(RetentionPolicy.RUNTIME)
@PreAuthorize("hasRole('ROLE_A') or hasRole('ROLE_B')")
public @interface ForAorB {
}
同时我也有
@Target(ElementType.METHOD)
@Retention(RetentionPolicy.RUNTIME)
@PreAuthorize("hasRole('ROLE_A')")
public @interface ForA {
}
和
@Target(ElementType.METHOD)
@Retention(RetentionPolicy.RUNTIME)
@PreAuthorize("hasRole('ROLE_B')")
public @interface ForB {
}
我的@PreAuthorize 表达式比简单的hasRole('ROLE_x) 更复杂一些,我不想在@ForA、@ForB 和@ForAorB 中将它们加倍。
是否可以基于@ForA 和@ForB 而不是在@PreAuthorize("hasRole('ROLE_A') or hasRole('ROLE_B')") 中加倍的表达式创建@ForAorB 注释?
我试过了,但看起来像
@Target(ElementType.METHOD)
@Retention(RetentionPolicy.RUNTIME)
@ForA @ForB
public @interface ForAorB {
}
实际上是 @ForAandB 但不是 @ForAorB
【问题讨论】:
标签: java spring spring-security annotations