Added support for secured channels and SecurityContext propagation within messages (INT-117).
This commit is contained in:
@@ -0,0 +1,59 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security;
|
||||
|
||||
import org.springframework.integration.handler.InterceptingMessageHandler;
|
||||
import org.springframework.integration.handler.MessageHandler;
|
||||
import org.springframework.integration.message.Message;
|
||||
import org.springframework.security.context.SecurityContext;
|
||||
import org.springframework.security.context.SecurityContextHolder;
|
||||
|
||||
/**
|
||||
* Associates the {@link SecurityContext} propagated in the message header
|
||||
* with the thread executing the handle call to a {@link MessageHandler}.
|
||||
*
|
||||
* @author Jonas Partner
|
||||
*/
|
||||
public class SecurityContextAssociatingHandlerInterceptor extends InterceptingMessageHandler {
|
||||
|
||||
public SecurityContextAssociatingHandlerInterceptor(MessageHandler target) {
|
||||
super(target);
|
||||
}
|
||||
|
||||
|
||||
@Override
|
||||
public Message<?> handle(Message<?> message, MessageHandler target) {
|
||||
if (message.getHeader().getAttributeNames().contains(
|
||||
SecurityContextPropagatingChannelInterceptor.SECURITY_CONTEXT_HEADER_ATTRIBUTE)) {
|
||||
return handleInSecurityContext(message, target);
|
||||
}
|
||||
return target.handle(message);
|
||||
}
|
||||
|
||||
private Message<?> handleInSecurityContext(Message<?> message, MessageHandler target) {
|
||||
SecurityContext context = (SecurityContext) message.getHeader().getAttribute(
|
||||
SecurityContextPropagatingChannelInterceptor.SECURITY_CONTEXT_HEADER_ATTRIBUTE);
|
||||
SecurityContextHolder.setContext(context);
|
||||
try{
|
||||
return target.handle(message);
|
||||
}
|
||||
finally {
|
||||
SecurityContextHolder.clearContext();
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,58 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security;
|
||||
|
||||
import org.apache.commons.logging.Log;
|
||||
import org.apache.commons.logging.LogFactory;
|
||||
|
||||
import org.springframework.integration.channel.MessageChannel;
|
||||
import org.springframework.integration.channel.interceptor.ChannelInterceptorAdapter;
|
||||
import org.springframework.integration.message.Message;
|
||||
import org.springframework.security.context.SecurityContext;
|
||||
import org.springframework.security.context.SecurityContextHolder;
|
||||
|
||||
/**
|
||||
* Propagates the {@ link SecurityContext} associated with the current
|
||||
* thread (if any) by adding it to the header of sent messages.
|
||||
*
|
||||
* @author Jonas Partner
|
||||
*/
|
||||
public class SecurityContextPropagatingChannelInterceptor extends ChannelInterceptorAdapter {
|
||||
|
||||
public static final String SECURITY_CONTEXT_HEADER_ATTRIBUTE = "SPRING_SECURITY_CONTEXT";
|
||||
|
||||
|
||||
private final Log logger = LogFactory.getLog(this.getClass());
|
||||
|
||||
|
||||
@Override
|
||||
public boolean preSend(Message<?> message, MessageChannel channel) {
|
||||
this.setSecurityContextAttribute(message);
|
||||
return true;
|
||||
}
|
||||
|
||||
protected void setSecurityContextAttribute(Message<?> message){
|
||||
SecurityContext securityContext = SecurityContextHolder.getContext();
|
||||
if (securityContext.getAuthentication() != null) {
|
||||
message.getHeader().setAttribute(SECURITY_CONTEXT_HEADER_ATTRIBUTE, securityContext);
|
||||
}
|
||||
else if (logger.isInfoEnabled()) {
|
||||
logger.info("No security context found");
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,102 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security;
|
||||
|
||||
import org.springframework.integration.channel.AbstractMessageChannel;
|
||||
import org.springframework.integration.channel.MessageChannel;
|
||||
import org.springframework.integration.channel.interceptor.ChannelInterceptorAdapter;
|
||||
import org.springframework.integration.message.Message;
|
||||
import org.springframework.security.AccessDecisionManager;
|
||||
import org.springframework.security.ConfigAttributeDefinition;
|
||||
import org.springframework.security.context.SecurityContextHolder;
|
||||
import org.springframework.util.Assert;
|
||||
|
||||
/**
|
||||
* Delegates to the provided instance of {@link AccessDecisionManager} to
|
||||
* enforce the security on the send and receive calls on the {@ MessageChannel}.
|
||||
*
|
||||
* @author Jonas Partner
|
||||
*/
|
||||
public class SecurityEnforcingChannelInterceptor extends ChannelInterceptorAdapter{
|
||||
|
||||
private final AccessDecisionManager accessDecisionManger;
|
||||
|
||||
private final String channelName;
|
||||
|
||||
private volatile ConfigAttributeDefinition sendSecurityAttributes;
|
||||
|
||||
private volatile ConfigAttributeDefinition receiveSecurityAttributes;
|
||||
|
||||
|
||||
public SecurityEnforcingChannelInterceptor(AccessDecisionManager accessDecisionManager, AbstractMessageChannel channelToSecure) {
|
||||
Assert.notNull(accessDecisionManager, "AccessDecisionManager must not be null");
|
||||
Assert.notNull(channelToSecure, "channel to secure must not be null");
|
||||
this.accessDecisionManger = accessDecisionManager;
|
||||
this.channelName = channelToSecure.getName();
|
||||
channelToSecure.addInterceptor(this);
|
||||
}
|
||||
|
||||
|
||||
public ConfigAttributeDefinition getSendSecurityAttributes() {
|
||||
return this.sendSecurityAttributes;
|
||||
}
|
||||
|
||||
public void setSendSecurityAttributes(ConfigAttributeDefinition sendSecurityAttributes) {
|
||||
this.sendSecurityAttributes = sendSecurityAttributes;
|
||||
}
|
||||
|
||||
public ConfigAttributeDefinition getReceiveSecurityAttributes() {
|
||||
return this.receiveSecurityAttributes;
|
||||
}
|
||||
|
||||
public void setReceiveSecurityAttributes(ConfigAttributeDefinition receiveSecurityAttributes) {
|
||||
this.receiveSecurityAttributes = receiveSecurityAttributes;
|
||||
}
|
||||
|
||||
@Override
|
||||
public boolean preSend(Message<?> message, MessageChannel channel) {
|
||||
this.checkSend(channel);
|
||||
return true;
|
||||
}
|
||||
|
||||
@Override
|
||||
public boolean preReceive(MessageChannel channel) {
|
||||
this.checkReceive(channel);
|
||||
return super.preReceive(channel);
|
||||
}
|
||||
|
||||
private void checkSend(MessageChannel channel){
|
||||
this.checkPermission(channel, this.sendSecurityAttributes);
|
||||
}
|
||||
|
||||
private void checkReceive(MessageChannel channel){
|
||||
this.checkPermission(channel, this.receiveSecurityAttributes);
|
||||
}
|
||||
|
||||
private void checkPermission(MessageChannel messageChannel, ConfigAttributeDefinition securityAttributes){
|
||||
if (securityAttributes != null) {
|
||||
this.accessDecisionManger.decide(SecurityContextHolder.getContext().getAuthentication(),
|
||||
messageChannel, securityAttributes);
|
||||
}
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return getClass().getName() + " for channel '" + this.channelName + "'";
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security.config;
|
||||
|
||||
import org.springframework.beans.factory.xml.NamespaceHandlerSupport;
|
||||
|
||||
/**
|
||||
* Namespace handler for the security namespace.
|
||||
*
|
||||
* @author Jonas Partner
|
||||
*/
|
||||
public class IntegrationSecurityNamespaceHandler extends NamespaceHandlerSupport {
|
||||
|
||||
public void init() {
|
||||
registerBeanDefinitionParser("secured", new SecuredParser());
|
||||
registerBeanDefinitionParser("secure-channels", new SecureChannelsParser());
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,56 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security.config;
|
||||
|
||||
import org.w3c.dom.Element;
|
||||
|
||||
import org.springframework.beans.factory.BeanDefinitionStoreException;
|
||||
import org.springframework.beans.factory.support.AbstractBeanDefinition;
|
||||
import org.springframework.beans.factory.support.BeanDefinitionBuilder;
|
||||
import org.springframework.beans.factory.xml.AbstractSingleBeanDefinitionParser;
|
||||
import org.springframework.beans.factory.xml.ParserContext;
|
||||
import org.springframework.security.context.SecurityContext;
|
||||
import org.springframework.util.StringUtils;
|
||||
|
||||
/**
|
||||
* Interprets the <secure-channels> element which controls default
|
||||
* {@link SecurityContext} propagation behaviour.
|
||||
*
|
||||
* @author Jonas Partner
|
||||
*/
|
||||
public class SecureChannelsParser extends AbstractSingleBeanDefinitionParser {
|
||||
|
||||
@Override
|
||||
protected void doParse(Element element, ParserContext parserContext, BeanDefinitionBuilder builder) {
|
||||
builder.getBeanDefinition().setAbstract(true);
|
||||
String propagation = element.getAttribute("propagate");
|
||||
boolean propagateByDefault = true;
|
||||
if (StringUtils.hasText(propagation)) {
|
||||
propagateByDefault = Boolean.parseBoolean(propagation);
|
||||
}
|
||||
if (propagateByDefault) {
|
||||
SecurityPropagatingBeanPostProcessorDefinitionHelper.setPropagationDefault(true, parserContext);
|
||||
}
|
||||
}
|
||||
|
||||
@Override
|
||||
protected String resolveId(Element element, AbstractBeanDefinition definition, ParserContext parserContext)
|
||||
throws BeanDefinitionStoreException {
|
||||
return "internal.integration.SecureChannels";
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,84 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security.config;
|
||||
|
||||
import org.w3c.dom.Element;
|
||||
|
||||
import org.springframework.beans.factory.support.BeanDefinitionBuilder;
|
||||
import org.springframework.beans.factory.xml.AbstractSingleBeanDefinitionParser;
|
||||
import org.springframework.beans.factory.xml.ParserContext;
|
||||
import org.springframework.integration.security.SecurityEnforcingChannelInterceptor;
|
||||
import org.springframework.security.ConfigAttributeDefinition;
|
||||
import org.springframework.security.context.SecurityContext;
|
||||
import org.springframework.util.StringUtils;
|
||||
|
||||
/**
|
||||
* Determines {@link SecurityContext} propagation behaviour for the parent element
|
||||
* channel, and creates a {@link SecurityEnforcingChannelInterceptor} to control
|
||||
* send and receive access if send-access and/or receive-access is specified.
|
||||
*
|
||||
* @author Jonas Partner
|
||||
*/
|
||||
public class SecuredParser extends AbstractSingleBeanDefinitionParser {
|
||||
|
||||
@Override
|
||||
protected boolean shouldGenerateId() {
|
||||
return false;
|
||||
}
|
||||
|
||||
@Override
|
||||
protected boolean shouldGenerateIdAsFallback() {
|
||||
return true;
|
||||
}
|
||||
|
||||
@Override
|
||||
protected void doParse(Element element, ParserContext parserContext, BeanDefinitionBuilder builder) {
|
||||
String receiveAccess = element.getAttribute("receive-access");
|
||||
String sendAccess = element.getAttribute("send-access");
|
||||
String accessDecisionManager = element.getAttribute("access-decision-manager");
|
||||
String propagation = element.getAttribute("propagate");
|
||||
String channelName = ((Element)element.getParentNode()).getAttribute("id");
|
||||
if (channelName == null) {
|
||||
parserContext.getReaderContext().error("The secured element requires a channel parent id.", element);
|
||||
}
|
||||
builder.getBeanDefinition().setBeanClass(SecurityEnforcingChannelInterceptor.class);
|
||||
if (!StringUtils.hasText(accessDecisionManager)) {
|
||||
accessDecisionManager = "accessDecisionManager";
|
||||
}
|
||||
builder.addConstructorArgReference(accessDecisionManager);
|
||||
builder.addConstructorArgReference(channelName);
|
||||
if (StringUtils.hasText(sendAccess)) {
|
||||
ConfigAttributeDefinition sendDefinition = new ConfigAttributeDefinition(sendAccess);
|
||||
builder.addPropertyValue("sendSecurityAttributes", sendDefinition);
|
||||
}
|
||||
if (StringUtils.hasText(receiveAccess)) {
|
||||
ConfigAttributeDefinition receiveDefinition = new ConfigAttributeDefinition(receiveAccess);
|
||||
builder.addPropertyValue("receiveSecurityAttributes", receiveDefinition);
|
||||
}
|
||||
boolean propagationValue = true;
|
||||
if (StringUtils.hasText(propagation)) {
|
||||
propagationValue = Boolean.parseBoolean(propagation);
|
||||
}
|
||||
if (propagationValue) {
|
||||
SecurityPropagatingBeanPostProcessorDefinitionHelper.addToIncludeChannelList(channelName, parserContext);
|
||||
}
|
||||
else {
|
||||
SecurityPropagatingBeanPostProcessorDefinitionHelper.addToExcludeChannelList(channelName, parserContext);
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,105 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security.config;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
import org.apache.commons.logging.Log;
|
||||
import org.apache.commons.logging.LogFactory;
|
||||
|
||||
import org.springframework.beans.BeansException;
|
||||
import org.springframework.beans.factory.config.BeanPostProcessor;
|
||||
import org.springframework.core.Ordered;
|
||||
import org.springframework.integration.channel.AbstractMessageChannel;
|
||||
import org.springframework.integration.security.SecurityContextPropagatingChannelInterceptor;
|
||||
|
||||
/**
|
||||
* Post processes channels applying appropriate propagation behaviour. If
|
||||
* default propagation is specified with a secure-channels tag, that will
|
||||
* be applied in the absence of a secured tag for the channel. If the
|
||||
* secured tag is specified, it will always determine propagation behaviour.
|
||||
*
|
||||
* @author Jonas Partner
|
||||
*/
|
||||
public class SecurityPropagatingBeanPostProcessor implements BeanPostProcessor, Ordered {
|
||||
|
||||
protected static final String SECURITY_PROPAGATING_BEAN_POST_PROCESSOR_NAME = SecurityPropagatingBeanPostProcessor.class.getName();
|
||||
|
||||
|
||||
private final SecurityContextPropagatingChannelInterceptor interceptor =
|
||||
new SecurityContextPropagatingChannelInterceptor();
|
||||
|
||||
private boolean propagateByDefault;
|
||||
|
||||
private final Log logger = LogFactory.getLog(this.getClass());
|
||||
|
||||
private List<String> channelsToInclude = new ArrayList<String>();
|
||||
|
||||
private List<String> channelsToExclude = new ArrayList<String>();
|
||||
|
||||
|
||||
public boolean isPropagateByDefault() {
|
||||
return this.propagateByDefault;
|
||||
}
|
||||
|
||||
public void setPropagateByDefault(boolean propagateByDefault) {
|
||||
this.propagateByDefault = propagateByDefault;
|
||||
}
|
||||
|
||||
public List<String> getChannelsToInclude() {
|
||||
return this.channelsToInclude;
|
||||
}
|
||||
|
||||
public void setChannelsToInclude(List<String> channelsToInclude) {
|
||||
this.channelsToInclude = channelsToInclude;
|
||||
}
|
||||
|
||||
public List<String> getChannelsToExclude() {
|
||||
return this.channelsToExclude;
|
||||
}
|
||||
|
||||
public void setChannelsToExclude(List<String> channelsToExclude) {
|
||||
this.channelsToExclude = channelsToExclude;
|
||||
}
|
||||
|
||||
public int getOrder() {
|
||||
return 0;
|
||||
}
|
||||
|
||||
public Object postProcessBeforeInitialization(Object bean, String beanName) throws BeansException {
|
||||
return bean;
|
||||
}
|
||||
|
||||
public Object postProcessAfterInitialization(Object bean, String beanName) throws BeansException {
|
||||
if (AbstractMessageChannel.class.isAssignableFrom(bean.getClass())) {
|
||||
AbstractMessageChannel channel = (AbstractMessageChannel) bean;
|
||||
if(this.channelsToInclude.contains(beanName) ||
|
||||
(this.propagateByDefault && !this.channelsToExclude.contains(beanName))) {
|
||||
channel.addInterceptor(this.interceptor);
|
||||
if (logger.isDebugEnabled()) {
|
||||
logger.debug("Channel '" + beanName + "' will propagate a SecurityContext.");
|
||||
}
|
||||
}
|
||||
else if (logger.isDebugEnabled()) {
|
||||
logger.debug("Channel '" + beanName + "' is not configured to propagate a SecurityContext.");
|
||||
}
|
||||
}
|
||||
return bean;
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,91 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security.config;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
import org.springframework.beans.factory.config.BeanDefinition;
|
||||
import org.springframework.beans.factory.config.RuntimeBeanNameReference;
|
||||
import org.springframework.beans.factory.parsing.BeanComponentDefinition;
|
||||
import org.springframework.beans.factory.support.RootBeanDefinition;
|
||||
import org.springframework.beans.factory.xml.ParserContext;
|
||||
import org.springframework.context.ApplicationContext;
|
||||
|
||||
/**
|
||||
* Helper to configure the per {@link ApplicationContext}
|
||||
* {@link SecurityPropagatingBeanPostProcessor} which determines
|
||||
* {@link SecurityContext} propagation.
|
||||
*
|
||||
* @author Jonas Partner
|
||||
*/
|
||||
public class SecurityPropagatingBeanPostProcessorDefinitionHelper {
|
||||
|
||||
private static final String CHANNELS_TO_INCLUDE = "channelsToInclude";
|
||||
|
||||
private static final String CHANNELS_TO_EXCLUDE = "channelsToExclude";
|
||||
|
||||
private static final String PROPAGATE_BY_DEFAULT = "propagateByDefault";
|
||||
|
||||
|
||||
public static void setPropagationDefault(boolean valueForPropagationDefault, ParserContext context) {
|
||||
BeanDefinition beanDefintion = getOrCreateSecurityPropagatingBeanPostProcessor(context);
|
||||
beanDefintion.getPropertyValues().addPropertyValue(PROPAGATE_BY_DEFAULT, Boolean.valueOf(valueForPropagationDefault));
|
||||
}
|
||||
|
||||
@SuppressWarnings("unchecked")
|
||||
public static void addToExcludeChannelList(String channelName, ParserContext context) {
|
||||
BeanDefinition beanDefintion = getOrCreateSecurityPropagatingBeanPostProcessor(context);
|
||||
List channelsToExclude;
|
||||
if (beanDefintion.getPropertyValues().contains(CHANNELS_TO_EXCLUDE)) {
|
||||
channelsToExclude = (List) beanDefintion.getPropertyValues().getPropertyValue(CHANNELS_TO_EXCLUDE).getValue();
|
||||
}
|
||||
else {
|
||||
channelsToExclude = new ArrayList<RuntimeBeanNameReference>();
|
||||
beanDefintion.getPropertyValues().addPropertyValue(CHANNELS_TO_EXCLUDE, channelsToExclude);
|
||||
}
|
||||
channelsToExclude.add(channelName);
|
||||
}
|
||||
|
||||
@SuppressWarnings("unchecked")
|
||||
public static void addToIncludeChannelList(String channelName, ParserContext context){
|
||||
BeanDefinition beanDefintion = getOrCreateSecurityPropagatingBeanPostProcessor(context);
|
||||
List channelsToExclude;
|
||||
if (beanDefintion.getPropertyValues().contains(CHANNELS_TO_INCLUDE)) {
|
||||
channelsToExclude = (List) beanDefintion.getPropertyValues().getPropertyValue(CHANNELS_TO_INCLUDE).getValue();
|
||||
}
|
||||
else {
|
||||
channelsToExclude = new ArrayList<RuntimeBeanNameReference>();
|
||||
beanDefintion.getPropertyValues().addPropertyValue(CHANNELS_TO_INCLUDE,channelsToExclude);
|
||||
}
|
||||
channelsToExclude.add(channelName);
|
||||
}
|
||||
|
||||
private static BeanDefinition getOrCreateSecurityPropagatingBeanPostProcessor(ParserContext context) {
|
||||
BeanDefinition beanDefinition = null;
|
||||
String postProcessorBeanName = SecurityPropagatingBeanPostProcessor.SECURITY_PROPAGATING_BEAN_POST_PROCESSOR_NAME;
|
||||
if (context.getRegistry().containsBeanDefinition(postProcessorBeanName)) {
|
||||
beanDefinition = context.getRegistry().getBeanDefinition(postProcessorBeanName);
|
||||
}
|
||||
if (beanDefinition == null) {
|
||||
beanDefinition = new RootBeanDefinition(SecurityPropagatingBeanPostProcessor.class);
|
||||
context.registerBeanComponent(new BeanComponentDefinition(beanDefinition, postProcessorBeanName));
|
||||
}
|
||||
return beanDefinition;
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,2 @@
|
||||
secured=org.springframework.integration.security.config.SecuredParser
|
||||
secure-channels=org.springframework.integration.security.config.SecureChannelsParser
|
||||
Reference in New Issue
Block a user