From 59a947bbe5bc5e140d3413f076425dc6d0123d99 Mon Sep 17 00:00:00 2001 From: Luke Taylor Date: Mon, 21 Jan 2008 15:06:43 +0000 Subject: [PATCH] SEC-636: Support for use of "ref" attribute in salt-source element. --- .../config/PasswordEncoderParser.java | 26 ++++++++++++------- .../security/config/auth-provider.xml | 15 ++++++++++- 2 files changed, 31 insertions(+), 10 deletions(-) diff --git a/core/src/main/java/org/springframework/security/config/PasswordEncoderParser.java b/core/src/main/java/org/springframework/security/config/PasswordEncoderParser.java index 3e3890ba82..ee526608ba 100644 --- a/core/src/main/java/org/springframework/security/config/PasswordEncoderParser.java +++ b/core/src/main/java/org/springframework/security/config/PasswordEncoderParser.java @@ -8,7 +8,9 @@ import org.springframework.security.providers.ldap.authenticator.LdapShaPassword import org.springframework.beans.factory.xml.BeanDefinitionParser; import org.springframework.beans.factory.xml.ParserContext; import org.springframework.beans.factory.config.BeanDefinition; +import org.springframework.beans.factory.config.RuntimeBeanReference; import org.springframework.beans.factory.support.RootBeanDefinition; +import org.springframework.beans.BeanMetadataElement; import org.springframework.util.StringUtils; import org.springframework.util.xml.DomUtils; @@ -48,7 +50,7 @@ public class PasswordEncoderParser { private Log logger = LogFactory.getLog(getClass()); - private BeanDefinition passwordEncoder; + private BeanMetadataElement passwordEncoder; private BeanDefinition saltSource; @@ -60,15 +62,21 @@ public class PasswordEncoderParser { String hash = element.getAttribute(ATT_HASH); boolean useBase64 = StringUtils.hasText(element.getAttribute(ATT_BASE_64)); - Class beanClass = (Class) ENCODER_CLASSES.get(hash); - passwordEncoder = new RootBeanDefinition(beanClass); + String ref = element.getAttribute(ATT_REF); - if (useBase64) { - if (beanClass.isAssignableFrom(BaseDigestPasswordEncoder.class)) { - passwordEncoder.getPropertyValues().addPropertyValue("encodeHashAsBase64", "true"); - } else { - logger.warn(ATT_BASE_64 + " isn't compatible with " + OPT_HASH_LDAP_SHA + " and will be ignored"); + if (StringUtils.hasText(ref)) { + passwordEncoder = new RuntimeBeanReference(ref); + } else { + Class beanClass = (Class) ENCODER_CLASSES.get(hash); + BeanDefinition beanDefinition = new RootBeanDefinition(beanClass); + if (useBase64) { + if (beanClass.isAssignableFrom(BaseDigestPasswordEncoder.class)) { + beanDefinition.getPropertyValues().addPropertyValue("encodeHashAsBase64", "true"); + } else { + logger.warn(ATT_BASE_64 + " isn't compatible with " + OPT_HASH_LDAP_SHA + " and will be ignored"); + } } + passwordEncoder = beanDefinition; } Element saltSourceElt = DomUtils.getChildElementByTagName(element, Elements.SALT_SOURCE); @@ -78,7 +86,7 @@ public class PasswordEncoderParser { } } - public BeanDefinition getPasswordEncoder() { + public BeanMetadataElement getPasswordEncoder() { return passwordEncoder; } diff --git a/core/src/test/resources/org/springframework/security/config/auth-provider.xml b/core/src/test/resources/org/springframework/security/config/auth-provider.xml index 8598cb05bb..393068609c 100644 --- a/core/src/test/resources/org/springframework/security/config/auth-provider.xml +++ b/core/src/test/resources/org/springframework/security/config/auth-provider.xml @@ -6,7 +6,7 @@ xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-2.0.xsd http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security-2.0.xsd"> - + @@ -34,4 +34,17 @@ http://www.springframework.org/schema/security http://www.springframework.org/sc + + + + + + + + + + + + + \ No newline at end of file