SEC-524: Added "var" attribute to authorize and accesscontrollist JSP tags.
Allows the result of the boolean condition granting/denying access to be stored in the page context for later use, without having to duplicate the tag.
This commit is contained in:
+27
-6
@@ -66,6 +66,7 @@ import org.springframework.web.util.ExpressionEvaluationUtils;
|
||||
* implementations are found in the application context.
|
||||
*
|
||||
* @author Ben Alex
|
||||
* @author Luke Taylor
|
||||
*/
|
||||
public class AccessControlListTag extends TagSupport {
|
||||
//~ Static fields/initializers =====================================================================================
|
||||
@@ -81,12 +82,13 @@ public class AccessControlListTag extends TagSupport {
|
||||
private SidRetrievalStrategy sidRetrievalStrategy;
|
||||
private PermissionFactory permissionFactory;
|
||||
private String hasPermission = "";
|
||||
private String var;
|
||||
|
||||
//~ Methods ========================================================================================================
|
||||
|
||||
public int doStartTag() throws JspException {
|
||||
if ((null == hasPermission) || "".equals(hasPermission)) {
|
||||
return Tag.SKIP_BODY;
|
||||
return skipBody();
|
||||
}
|
||||
|
||||
initializeIfRequired();
|
||||
@@ -111,7 +113,7 @@ public class AccessControlListTag extends TagSupport {
|
||||
}
|
||||
|
||||
// Of course they have access to a null object!
|
||||
return Tag.EVAL_BODY_INCLUDE;
|
||||
return evalBody();
|
||||
}
|
||||
|
||||
if (SecurityContextHolder.getContext().getAuthentication() == null) {
|
||||
@@ -120,7 +122,7 @@ public class AccessControlListTag extends TagSupport {
|
||||
"SecurityContextHolder did not return a non-null Authentication object, so skipping tag body");
|
||||
}
|
||||
|
||||
return Tag.SKIP_BODY;
|
||||
return skipBody();
|
||||
}
|
||||
|
||||
List<Sid> sids = sidRetrievalStrategy.getSids(SecurityContextHolder.getContext().getAuthentication());
|
||||
@@ -131,15 +133,30 @@ public class AccessControlListTag extends TagSupport {
|
||||
Acl acl = aclService.readAclById(oid, sids);
|
||||
|
||||
if (acl.isGranted(requiredPermissions, sids, false)) {
|
||||
return Tag.EVAL_BODY_INCLUDE;
|
||||
return evalBody();
|
||||
} else {
|
||||
return Tag.SKIP_BODY;
|
||||
return skipBody();
|
||||
}
|
||||
} catch (NotFoundException nfe) {
|
||||
return Tag.SKIP_BODY;
|
||||
return skipBody();
|
||||
}
|
||||
}
|
||||
|
||||
private int skipBody() {
|
||||
if (var != null) {
|
||||
pageContext.setAttribute(var, Boolean.FALSE, PageContext.PAGE_SCOPE);
|
||||
}
|
||||
return SKIP_BODY;
|
||||
}
|
||||
|
||||
private int evalBody() {
|
||||
if (var != null) {
|
||||
pageContext.setAttribute(var, Boolean.TRUE, PageContext.PAGE_SCOPE);
|
||||
}
|
||||
return EVAL_BODY_INCLUDE;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Allows test cases to override where application context obtained from.
|
||||
*
|
||||
@@ -233,4 +250,8 @@ public class AccessControlListTag extends TagSupport {
|
||||
public void setHasPermission(String hasPermission) {
|
||||
this.hasPermission = hasPermission;
|
||||
}
|
||||
|
||||
public void setVar(String var) {
|
||||
this.var = var;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -10,6 +10,7 @@ import javax.servlet.ServletRequest;
|
||||
import javax.servlet.ServletResponse;
|
||||
import javax.servlet.http.HttpServletRequest;
|
||||
import javax.servlet.jsp.JspException;
|
||||
import javax.servlet.jsp.PageContext;
|
||||
|
||||
import org.springframework.context.ApplicationContext;
|
||||
import org.springframework.expression.Expression;
|
||||
@@ -35,6 +36,7 @@ public class AuthorizeTag extends LegacyAuthorizeTag {
|
||||
private String access;
|
||||
private String url;
|
||||
private String method;
|
||||
private String var;
|
||||
|
||||
// If access expression evaluates to "true" return
|
||||
public int doStartTag() throws JspException {
|
||||
@@ -44,13 +46,21 @@ public class AuthorizeTag extends LegacyAuthorizeTag {
|
||||
return SKIP_BODY;
|
||||
}
|
||||
|
||||
int result;
|
||||
|
||||
if (access != null && access.length() > 0) {
|
||||
return authorizeUsingAccessExpression(currentUser);
|
||||
result = authorizeUsingAccessExpression(currentUser);
|
||||
} else if (url != null && url.length() > 0) {
|
||||
return authorizeUsingUrlCheck(currentUser);
|
||||
result = authorizeUsingUrlCheck(currentUser);
|
||||
} else {
|
||||
result = super.doStartTag();
|
||||
}
|
||||
|
||||
return super.doStartTag();
|
||||
if (var != null) {
|
||||
pageContext.setAttribute(var, Boolean.valueOf(result == EVAL_BODY_INCLUDE), PageContext.PAGE_SCOPE);
|
||||
}
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
private int authorizeUsingAccessExpression(Authentication currentUser) throws JspException {
|
||||
@@ -91,6 +101,10 @@ public class AuthorizeTag extends LegacyAuthorizeTag {
|
||||
this.method = method;
|
||||
}
|
||||
|
||||
public void setVar(String var) {
|
||||
this.var = var;
|
||||
}
|
||||
|
||||
WebSecurityExpressionHandler getExpressionHandler() throws JspException {
|
||||
ServletContext servletContext = pageContext.getServletContext();
|
||||
ApplicationContext ctx = WebApplicationContextUtils.getRequiredWebApplicationContext(servletContext);
|
||||
|
||||
@@ -9,7 +9,6 @@
|
||||
<uri>http://www.springframework.org/security/tags</uri>
|
||||
<description>
|
||||
Spring Security Authorization Tag Library
|
||||
$Id$
|
||||
</description>
|
||||
|
||||
<tag>
|
||||
@@ -51,6 +50,15 @@
|
||||
</description>
|
||||
</attribute>
|
||||
|
||||
<attribute>
|
||||
<name>var</name>
|
||||
<required>false</required>
|
||||
<rtexprvalue>false</rtexprvalue>
|
||||
<description>
|
||||
A page scoped variable into which the boolean result of the tag evaluation will be written, allowing the
|
||||
same condition to be reused subsequently in the page without re-evaluation.
|
||||
</description>
|
||||
</attribute>
|
||||
|
||||
<attribute>
|
||||
<name>ifNotGranted</name>
|
||||
@@ -153,6 +161,15 @@
|
||||
are being evaluated.
|
||||
</description>
|
||||
</attribute>
|
||||
<attribute>
|
||||
<name>var</name>
|
||||
<required>false</required>
|
||||
<rtexprvalue>false</rtexprvalue>
|
||||
<description>
|
||||
A page scoped variable into which the boolean result of the tag evaluation will be written, allowing the
|
||||
same condition to be reused subsequently in the page without re-evaluation.
|
||||
</description>
|
||||
</attribute>
|
||||
</tag>
|
||||
|
||||
</taglib>
|
||||
|
||||
+8
-5
@@ -1,6 +1,6 @@
|
||||
package org.springframework.security.taglibs.authz;
|
||||
|
||||
import static org.junit.Assert.assertEquals;
|
||||
import static org.junit.Assert.*;
|
||||
import static org.mockito.Matchers.*;
|
||||
import static org.mockito.Mockito.*;
|
||||
|
||||
@@ -33,6 +33,7 @@ import org.springframework.web.context.WebApplicationContext;
|
||||
public class AccessControlListTagTests {
|
||||
AccessControlListTag tag;
|
||||
Acl acl;
|
||||
MockPageContext pageContext;
|
||||
|
||||
@Before
|
||||
public void setup() {
|
||||
@@ -44,9 +45,6 @@ public class AccessControlListTagTests {
|
||||
ObjectIdentity oid = mock(ObjectIdentity.class);
|
||||
ObjectIdentityRetrievalStrategy oidStrategy = mock(ObjectIdentityRetrievalStrategy.class);
|
||||
when(oidStrategy.getObjectIdentity(anyObject())).thenReturn(oid);
|
||||
// AclPermissionEvaluator pe = new AclPermissionEvaluator(service);
|
||||
// pe.setObjectIdentityRetrievalStrategy(oidStrategy);
|
||||
// pe.setSidRetrievalStrategy(mock(SidRetrievalStrategy.class));
|
||||
acl = mock(Acl.class);
|
||||
|
||||
when(service.readAclById(any(ObjectIdentity.class), anyList())).thenReturn(acl);
|
||||
@@ -59,7 +57,8 @@ public class AccessControlListTagTests {
|
||||
|
||||
MockServletContext servletCtx = new MockServletContext();
|
||||
servletCtx.setAttribute(WebApplicationContext.ROOT_WEB_APPLICATION_CONTEXT_ATTRIBUTE, ctx);
|
||||
tag.setPageContext(new MockPageContext(servletCtx, new MockHttpServletRequest(), new MockHttpServletResponse()));
|
||||
pageContext = new MockPageContext(servletCtx, new MockHttpServletRequest(), new MockHttpServletResponse());
|
||||
tag.setPageContext(pageContext);
|
||||
}
|
||||
|
||||
@After
|
||||
@@ -73,8 +72,10 @@ public class AccessControlListTagTests {
|
||||
|
||||
tag.setDomainObject(new Object());
|
||||
tag.setHasPermission("READ");
|
||||
tag.setVar("allowed");
|
||||
|
||||
assertEquals(Tag.EVAL_BODY_INCLUDE, tag.doStartTag());
|
||||
assertTrue((Boolean)pageContext.getAttribute("allowed"));
|
||||
}
|
||||
|
||||
@Test
|
||||
@@ -83,8 +84,10 @@ public class AccessControlListTagTests {
|
||||
|
||||
tag.setDomainObject(new Object());
|
||||
tag.setHasPermission("READ");
|
||||
tag.setVar("allowed");
|
||||
|
||||
assertEquals(Tag.SKIP_BODY, tag.doStartTag());
|
||||
assertFalse((Boolean)pageContext.getAttribute("allowed"));
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user