1
0
mirror of synced 2026-08-05 01:36:56 +00:00

SEC-2045: AbstractAuthorizeTag supports custom WebInvocationPrivilegeEvaluator

This commit is contained in:
Rob Winch
2012-10-04 11:34:36 -05:00
parent 4f741bc914
commit f38df99730
3 changed files with 108 additions and 0 deletions
@@ -1,9 +1,12 @@
package org.springframework.security.web;
import org.springframework.security.web.access.WebInvocationPrivilegeEvaluator;
/**
* Well-known keys which are used to store Spring Security information in request or session scope.
*
* @author Luke Taylor
* @author Rob Winch
* @since 3.0.3
*/
public final class WebAttributes {
@@ -20,4 +23,12 @@ public final class WebAttributes {
* @see org.springframework.security.web.authentication.SimpleUrlAuthenticationFailureHandler
*/
public static final String AUTHENTICATION_EXCEPTION = "SPRING_SECURITY_LAST_EXCEPTION";
/**
* Set as a request attribute to override the default {@link WebInvocationPrivilegeEvaluator}
*
* @see WebInvocationPrivilegeEvaluator
* @since 3.1.3
*/
public static final String WEB_INVOCATION_PRIVILEGE_EVALUATOR_ATTRIBUTE = WebAttributes.class.getName() + ".WEB_INVOCATION_PRIVILEGE_EVALUATOR_ATTRIBUTE";
}