refactored security namespace to use separate schema

This commit is contained in:
Jonas Partner
2008-06-25 17:29:32 +00:00
parent a2a40bca4d
commit 5709c4e144
32 changed files with 997 additions and 549 deletions

View File

@@ -0,0 +1,80 @@
/*
* Copyright 2002-2008 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.integration.security;
import java.util.ArrayList;
import java.util.List;
import java.util.regex.Pattern;
import org.springframework.beans.BeansException;
import org.springframework.beans.factory.config.BeanPostProcessor;
import org.springframework.core.Ordered;
import org.springframework.integration.channel.AbstractMessageChannel;
import org.springframework.integration.channel.ChannelInterceptor;
/**
* Registers the provided {@link ChannelInterceptor} instance with any
* {@link AbstractMessageChannel} with a name matching the provided pattern
* @author Jonas Partner
*
*/
public class ChannelInterceptorRegisteringBeanPostProcessor implements BeanPostProcessor, Ordered {
private final ChannelInterceptor channelInterceptor;
private final List<Pattern> regexpPatterns;
private int order;
public ChannelInterceptorRegisteringBeanPostProcessor(ChannelInterceptor channelInterceptor, List<String> patterns) {
this.channelInterceptor = channelInterceptor;
this.regexpPatterns = new ArrayList<Pattern>();
for (String stringPattern : patterns) {
regexpPatterns.add(Pattern.compile(stringPattern));
}
}
public Object postProcessAfterInitialization(Object bean, String beanName) throws BeansException {
if (AbstractMessageChannel.class.isAssignableFrom(bean.getClass()) && matchesPattern(beanName)) {
((AbstractMessageChannel) bean).addInterceptor(channelInterceptor);
}
return bean;
}
public Object postProcessBeforeInitialization(Object bean, String beanName) throws BeansException {
return bean;
}
public int getOrder() {
return order;
}
public void setOrder(int order) {
this.order = order;
}
protected boolean matchesPattern(String beanName) {
for (Pattern regexpPattern : regexpPatterns) {
if (regexpPattern.matcher(beanName).matches()) {
return true;
}
}
return false;
}
}

View File

@@ -23,44 +23,42 @@ import org.springframework.security.context.SecurityContext;
import org.springframework.security.context.SecurityContextHolder;
/**
* Associates the {@link SecurityContext} propagated in the message header
* with the thread executing the handle call to a {@link MessageHandler}.
* Associates the {@link SecurityContext} propagated in the message header with
* the thread executing the handle call to a {@link MessageHandler}.
*
* @author Jonas Partner
*/
public class SecurityContextAssociatingHandlerInterceptor extends InterceptingMessageHandler {
/**
* One time only set the strategy to be stack based to allow use of direct channels where push and pop is required rather than set and clear
* One time only set the strategy to be stack based to allow use of direct
* channels where push and pop is required rather than set and clear
*/
static {
SecurityContextHolder.setStrategyName(StackBasedSecurityContextHolderStrategy.class.getName());
}
public SecurityContextAssociatingHandlerInterceptor(MessageHandler target) {
super(target);
}
@Override
public Message<?> handle(Message<?> message, MessageHandler target) {
if (message.getHeader().getAttributeNames().contains(
SecurityContextPropagatingChannelInterceptor.SECURITY_CONTEXT_HEADER_ATTRIBUTE)) {
if (message.getHeader().getAttributeNames().contains(SecurityContextUtils.SECURITY_CONTEXT_HEADER_ATTRIBUTE)) {
return handleInSecurityContext(message, target);
}
return target.handle(message);
}
private Message<?> handleInSecurityContext(Message<?> message, MessageHandler target) {
SecurityContext context = (SecurityContext) message.getHeader().getAttribute(
SecurityContextPropagatingChannelInterceptor.SECURITY_CONTEXT_HEADER_ATTRIBUTE);
SecurityContext context = SecurityContextUtils.getSecurityContextFromHeader(message);
SecurityContextHolder.setContext(context);
try{
try {
return target.handle(message);
}
finally {
SecurityContextHolder.clearContext();
}
}
}
}

View File

@@ -1,58 +0,0 @@
/*
* Copyright 2002-2008 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.integration.security;
import org.apache.commons.logging.Log;
import org.apache.commons.logging.LogFactory;
import org.springframework.integration.channel.MessageChannel;
import org.springframework.integration.channel.interceptor.ChannelInterceptorAdapter;
import org.springframework.integration.message.Message;
import org.springframework.security.context.SecurityContext;
import org.springframework.security.context.SecurityContextHolder;
/**
* Propagates the {@ link SecurityContext} associated with the current
* thread (if any) by adding it to the header of sent messages.
*
* @author Jonas Partner
*/
public class SecurityContextPropagatingChannelInterceptor extends ChannelInterceptorAdapter {
public static final String SECURITY_CONTEXT_HEADER_ATTRIBUTE = "SPRING_SECURITY_CONTEXT";
private final Log logger = LogFactory.getLog(this.getClass());
@Override
public boolean preSend(Message<?> message, MessageChannel channel) {
this.setSecurityContextAttribute(message);
return true;
}
protected void setSecurityContextAttribute(Message<?> message){
SecurityContext securityContext = SecurityContextHolder.getContext();
if (securityContext.getAuthentication() != null) {
message.getHeader().setAttribute(SECURITY_CONTEXT_HEADER_ATTRIBUTE, securityContext);
}
else if (logger.isInfoEnabled()) {
logger.info("No security context found");
}
}
}

View File

@@ -0,0 +1,38 @@
/*
* Copyright 2002-2008 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.integration.security;
import org.springframework.integration.message.Message;
import org.springframework.security.context.SecurityContext;
/**
* @author Jonas Partner
*
*/
public class SecurityContextUtils {
public static final String SECURITY_CONTEXT_HEADER_ATTRIBUTE = "SPRING_SECURITY_CONTEXT";
public static SecurityContext getSecurityContextFromHeader(Message<?> message) {
return (SecurityContext) message.getHeader().getAttribute(SECURITY_CONTEXT_HEADER_ATTRIBUTE);
}
public static void setSecurityContextHeader(SecurityContext sctx, Message<?> message) {
message.getHeader().setAttribute(SECURITY_CONTEXT_HEADER_ATTRIBUTE, sctx);
}
}

View File

@@ -1,102 +0,0 @@
/*
* Copyright 2002-2008 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.integration.security;
import org.springframework.integration.channel.AbstractMessageChannel;
import org.springframework.integration.channel.MessageChannel;
import org.springframework.integration.channel.interceptor.ChannelInterceptorAdapter;
import org.springframework.integration.message.Message;
import org.springframework.security.AccessDecisionManager;
import org.springframework.security.ConfigAttributeDefinition;
import org.springframework.security.context.SecurityContextHolder;
import org.springframework.util.Assert;
/**
* Delegates to the provided instance of {@link AccessDecisionManager} to
* enforce the security on the send and receive calls on the {@ MessageChannel}.
*
* @author Jonas Partner
*/
public class SecurityEnforcingChannelInterceptor extends ChannelInterceptorAdapter{
private final AccessDecisionManager accessDecisionManger;
private final String channelName;
private volatile ConfigAttributeDefinition sendSecurityAttributes;
private volatile ConfigAttributeDefinition receiveSecurityAttributes;
public SecurityEnforcingChannelInterceptor(AccessDecisionManager accessDecisionManager, AbstractMessageChannel channelToSecure) {
Assert.notNull(accessDecisionManager, "AccessDecisionManager must not be null");
Assert.notNull(channelToSecure, "channel to secure must not be null");
this.accessDecisionManger = accessDecisionManager;
this.channelName = channelToSecure.getName();
channelToSecure.addInterceptor(this);
}
public ConfigAttributeDefinition getSendSecurityAttributes() {
return this.sendSecurityAttributes;
}
public void setSendSecurityAttributes(ConfigAttributeDefinition sendSecurityAttributes) {
this.sendSecurityAttributes = sendSecurityAttributes;
}
public ConfigAttributeDefinition getReceiveSecurityAttributes() {
return this.receiveSecurityAttributes;
}
public void setReceiveSecurityAttributes(ConfigAttributeDefinition receiveSecurityAttributes) {
this.receiveSecurityAttributes = receiveSecurityAttributes;
}
@Override
public boolean preSend(Message<?> message, MessageChannel channel) {
this.checkSend(channel);
return true;
}
@Override
public boolean preReceive(MessageChannel channel) {
this.checkReceive(channel);
return super.preReceive(channel);
}
private void checkSend(MessageChannel channel){
this.checkPermission(channel, this.sendSecurityAttributes);
}
private void checkReceive(MessageChannel channel){
this.checkPermission(channel, this.receiveSecurityAttributes);
}
private void checkPermission(MessageChannel messageChannel, ConfigAttributeDefinition securityAttributes){
if (securityAttributes != null) {
this.accessDecisionManger.decide(SecurityContextHolder.getContext().getAuthentication(),
messageChannel, securityAttributes);
}
}
@Override
public String toString() {
return getClass().getName() + " for channel '" + this.channelName + "'";
}
}

View File

@@ -0,0 +1,55 @@
/*
* Copyright 2002-2008 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.integration.security.channel;
import org.apache.commons.logging.Log;
import org.apache.commons.logging.LogFactory;
import org.springframework.integration.channel.MessageChannel;
import org.springframework.integration.channel.interceptor.ChannelInterceptorAdapter;
import org.springframework.integration.message.Message;
import org.springframework.integration.security.SecurityContextUtils;
import org.springframework.security.context.SecurityContext;
import org.springframework.security.context.SecurityContextHolder;
/**
* Propagates the {@ link SecurityContext} associated with the current thread
* (if any) by adding it to the header of sent messages.
*
* @author Jonas Partner
*/
public class SecurityContextPropagatingChannelInterceptor extends ChannelInterceptorAdapter {
private final Log logger = LogFactory.getLog(this.getClass());
@Override
public boolean preSend(Message<?> message, MessageChannel channel) {
this.setSecurityContextAttribute(message);
return true;
}
protected void setSecurityContextAttribute(Message<?> message) {
SecurityContext securityContext = SecurityContextHolder.getContext();
if (securityContext.getAuthentication() != null) {
SecurityContextUtils.setSecurityContextHeader(securityContext, message);
}
else if (logger.isInfoEnabled()) {
logger.info("No security context found");
}
}
}

View File

@@ -0,0 +1,90 @@
/*
* Copyright 2002-2008 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.integration.security.channel;
import org.springframework.integration.channel.AbstractMessageChannel;
import org.springframework.integration.channel.MessageChannel;
import org.springframework.integration.channel.interceptor.ChannelInterceptorAdapter;
import org.springframework.integration.message.Message;
import org.springframework.security.AccessDecisionManager;
import org.springframework.security.ConfigAttributeDefinition;
import org.springframework.security.context.SecurityContextHolder;
import org.springframework.util.Assert;
/**
* Delegates to the provided instance of {@link AccessDecisionManager} to
* enforce the security on the send and receive calls on the {@ MessageChannel}.
*
* @author Jonas Partner
*/
public class SecurityEnforcingChannelInterceptor extends ChannelInterceptorAdapter {
private final AccessDecisionManager accessDecisionManger;
private volatile ConfigAttributeDefinition sendSecurityAttributes;
private volatile ConfigAttributeDefinition receiveSecurityAttributes;
public SecurityEnforcingChannelInterceptor(AccessDecisionManager accessDecisionManager) {
Assert.notNull(accessDecisionManager, "AccessDecisionManager must not be null");
this.accessDecisionManger = accessDecisionManager;
}
public ConfigAttributeDefinition getSendSecurityAttributes() {
return this.sendSecurityAttributes;
}
public void setSendSecurityAttributes(ConfigAttributeDefinition sendSecurityAttributes) {
this.sendSecurityAttributes = sendSecurityAttributes;
}
public ConfigAttributeDefinition getReceiveSecurityAttributes() {
return this.receiveSecurityAttributes;
}
public void setReceiveSecurityAttributes(ConfigAttributeDefinition receiveSecurityAttributes) {
this.receiveSecurityAttributes = receiveSecurityAttributes;
}
@Override
public boolean preSend(Message<?> message, MessageChannel channel) {
this.checkSend(channel);
return true;
}
@Override
public boolean preReceive(MessageChannel channel) {
this.checkReceive(channel);
return super.preReceive(channel);
}
private void checkSend(MessageChannel channel) {
this.checkPermission(channel, this.sendSecurityAttributes);
}
private void checkReceive(MessageChannel channel) {
this.checkPermission(channel, this.receiveSecurityAttributes);
}
private void checkPermission(MessageChannel messageChannel, ConfigAttributeDefinition securityAttributes) {
if (securityAttributes != null) {
this.accessDecisionManger.decide(SecurityContextHolder.getContext().getAuthentication(), messageChannel,
securityAttributes);
}
}
}

View File

@@ -26,8 +26,8 @@ import org.springframework.beans.factory.xml.NamespaceHandlerSupport;
public class IntegrationSecurityNamespaceHandler extends NamespaceHandlerSupport {
public void init() {
registerBeanDefinitionParser("secured", new SecuredParser());
registerBeanDefinitionParser("secure-channels", new SecureChannelsParser());
registerBeanDefinitionParser("secured-channels", new SecuredChannelsParser());
registerBeanDefinitionParser("security-propagating-channels", new SecurityPropagatingChannelsParser());
}
}

View File

@@ -1,56 +0,0 @@
/*
* Copyright 2002-2008 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.integration.security.config;
import org.w3c.dom.Element;
import org.springframework.beans.factory.BeanDefinitionStoreException;
import org.springframework.beans.factory.support.AbstractBeanDefinition;
import org.springframework.beans.factory.support.BeanDefinitionBuilder;
import org.springframework.beans.factory.xml.AbstractSingleBeanDefinitionParser;
import org.springframework.beans.factory.xml.ParserContext;
import org.springframework.security.context.SecurityContext;
import org.springframework.util.StringUtils;
/**
* Interprets the &lt;secure-channels&gt; element which controls default
* {@link SecurityContext} propagation behaviour.
*
* @author Jonas Partner
*/
public class SecureChannelsParser extends AbstractSingleBeanDefinitionParser {
@Override
protected void doParse(Element element, ParserContext parserContext, BeanDefinitionBuilder builder) {
builder.getBeanDefinition().setAbstract(true);
String propagation = element.getAttribute("propagate");
boolean propagateByDefault = true;
if (StringUtils.hasText(propagation)) {
propagateByDefault = Boolean.parseBoolean(propagation);
}
if (propagateByDefault) {
SecurityPropagatingBeanPostProcessorDefinitionHelper.setPropagationDefault(true, parserContext);
}
}
@Override
protected String resolveId(Element element, AbstractBeanDefinition definition, ParserContext parserContext)
throws BeanDefinitionStoreException {
return "internal.integration.SecureChannels";
}
}

View File

@@ -0,0 +1,126 @@
/*
* Copyright 2002-2008 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.integration.security.config;
import java.util.ArrayList;
import java.util.List;
import org.springframework.beans.factory.config.BeanDefinition;
import org.springframework.beans.factory.config.ConstructorArgumentValues.ValueHolder;
import org.springframework.beans.factory.support.BeanDefinitionBuilder;
import org.springframework.beans.factory.xml.AbstractSingleBeanDefinitionParser;
import org.springframework.beans.factory.xml.ParserContext;
import org.springframework.integration.security.ChannelInterceptorRegisteringBeanPostProcessor;
import org.springframework.integration.security.channel.SecurityEnforcingChannelInterceptor;
import org.springframework.security.ConfigAttributeDefinition;
import org.springframework.security.context.SecurityContext;
import org.springframework.util.StringUtils;
import org.w3c.dom.Element;
import org.w3c.dom.NodeList;
/**
* Determines {@link SecurityContext} propagation behaviour for the parent
* element channel, and creates a {@link SecurityEnforcingChannelInterceptor} to
* control send and receive access if send-access and/or receive-access is
* specified.
*
* @author Jonas Partner
*/
public class SecuredChannelsParser extends AbstractSingleBeanDefinitionParser {
public SecuredChannelsParser() {
super();
}
@Override
protected boolean shouldGenerateId() {
return true;
}
@Override
protected boolean shouldGenerateIdAsFallback() {
return true;
}
@Override
protected void doParse(Element element, ParserContext parserContext, BeanDefinitionBuilder builder) {
String receiveAccess = element.getAttribute("receive-access");
String sendAccess = element.getAttribute("send-access");
String accessDecisionManager = element.getAttribute("access-decision-manager");
String propagation = element.getAttribute("propagate");
BeanDefinition interceptorBeanDefinition = createSecurityEnforcingChannelInterceptor(accessDecisionManager,
sendAccess, receiveAccess);
List<String> patternList = processPatterns(element.getElementsByTagNameNS(element.getNamespaceURI(),
"channel-name-pattern"));
builder.getBeanDefinition().setBeanClass(ChannelInterceptorRegisteringBeanPostProcessor.class);
builder.getBeanDefinition().getConstructorArgumentValues().addGenericArgumentValue(
new ValueHolder(interceptorBeanDefinition));
builder.getBeanDefinition().getConstructorArgumentValues()
.addGenericArgumentValue(new ValueHolder(patternList));
setPropagation(Boolean.parseBoolean(propagation), patternList, parserContext);
}
protected List<String> processPatterns(NodeList patternList) {
List<String> patterns = new ArrayList<String>();
for (int i = 0; i < patternList.getLength(); i++) {
Element patternElement = (Element) patternList.item(i);
patterns.add(patternElement.getTextContent());
}
return patterns;
}
protected void setPropagation(boolean propagation, List<String> patterns, ParserContext parserContext) {
for (String pattern : patterns) {
if (propagation) {
SecurityPropagatingBeanPostProcessorDefinitionHelper.addToIncludeChannelList(pattern, parserContext);
}
else {
SecurityPropagatingBeanPostProcessorDefinitionHelper.addToExcludeChannelList(pattern, parserContext);
}
}
}
protected BeanDefinition createSecurityEnforcingChannelInterceptor(String accessDecisionManager, String sendAccess,
String receiveAccess) {
if (!StringUtils.hasText(accessDecisionManager)) {
accessDecisionManager = "accessDecisionManager";
}
BeanDefinitionBuilder beanDefinitionBuilder = BeanDefinitionBuilder
.genericBeanDefinition(SecurityEnforcingChannelInterceptor.class);
beanDefinitionBuilder.addConstructorArgReference(accessDecisionManager);
if (StringUtils.hasText(sendAccess)) {
ConfigAttributeDefinition sendDefinition = new ConfigAttributeDefinition(StringUtils.tokenizeToStringArray(
sendAccess, ","));
beanDefinitionBuilder.addPropertyValue("sendSecurityAttributes", sendDefinition);
}
if (StringUtils.hasText(receiveAccess)) {
ConfigAttributeDefinition receiveDefinition = new ConfigAttributeDefinition(StringUtils
.tokenizeToStringArray(receiveAccess, ","));
beanDefinitionBuilder.addPropertyValue("receiveSecurityAttributes", receiveDefinition);
}
return beanDefinitionBuilder.getBeanDefinition();
}
}

View File

@@ -1,84 +0,0 @@
/*
* Copyright 2002-2008 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.integration.security.config;
import org.w3c.dom.Element;
import org.springframework.beans.factory.support.BeanDefinitionBuilder;
import org.springframework.beans.factory.xml.AbstractSingleBeanDefinitionParser;
import org.springframework.beans.factory.xml.ParserContext;
import org.springframework.integration.security.SecurityEnforcingChannelInterceptor;
import org.springframework.security.ConfigAttributeDefinition;
import org.springframework.security.context.SecurityContext;
import org.springframework.util.StringUtils;
/**
* Determines {@link SecurityContext} propagation behaviour for the parent element
* channel, and creates a {@link SecurityEnforcingChannelInterceptor} to control
* send and receive access if send-access and/or receive-access is specified.
*
* @author Jonas Partner
*/
public class SecuredParser extends AbstractSingleBeanDefinitionParser {
@Override
protected boolean shouldGenerateId() {
return false;
}
@Override
protected boolean shouldGenerateIdAsFallback() {
return true;
}
@Override
protected void doParse(Element element, ParserContext parserContext, BeanDefinitionBuilder builder) {
String receiveAccess = element.getAttribute("receive-access");
String sendAccess = element.getAttribute("send-access");
String accessDecisionManager = element.getAttribute("access-decision-manager");
String propagation = element.getAttribute("propagate");
String channelName = ((Element)element.getParentNode()).getAttribute("id");
if (channelName == null) {
parserContext.getReaderContext().error("The secured element requires a channel parent id.", element);
}
builder.getBeanDefinition().setBeanClass(SecurityEnforcingChannelInterceptor.class);
if (!StringUtils.hasText(accessDecisionManager)) {
accessDecisionManager = "accessDecisionManager";
}
builder.addConstructorArgReference(accessDecisionManager);
builder.addConstructorArgReference(channelName);
if (StringUtils.hasText(sendAccess)) {
ConfigAttributeDefinition sendDefinition = new ConfigAttributeDefinition(sendAccess);
builder.addPropertyValue("sendSecurityAttributes", sendDefinition);
}
if (StringUtils.hasText(receiveAccess)) {
ConfigAttributeDefinition receiveDefinition = new ConfigAttributeDefinition(receiveAccess);
builder.addPropertyValue("receiveSecurityAttributes", receiveDefinition);
}
boolean propagationValue = true;
if (StringUtils.hasText(propagation)) {
propagationValue = Boolean.parseBoolean(propagation);
}
if (propagationValue) {
SecurityPropagatingBeanPostProcessorDefinitionHelper.addToIncludeChannelList(channelName, parserContext);
}
else {
SecurityPropagatingBeanPostProcessorDefinitionHelper.addToExcludeChannelList(channelName, parserContext);
}
}
}

View File

@@ -18,40 +18,38 @@ package org.springframework.integration.security.config;
import java.util.ArrayList;
import java.util.List;
import java.util.regex.Pattern;
import org.apache.commons.logging.Log;
import org.apache.commons.logging.LogFactory;
import org.springframework.beans.BeansException;
import org.springframework.beans.factory.config.BeanPostProcessor;
import org.springframework.core.Ordered;
import org.springframework.integration.channel.AbstractMessageChannel;
import org.springframework.integration.security.SecurityContextPropagatingChannelInterceptor;
import org.springframework.integration.security.channel.SecurityContextPropagatingChannelInterceptor;
/**
* Post processes channels applying appropriate propagation behaviour. If
* default propagation is specified with a secure-channels tag, that will
* be applied in the absence of a secured tag for the channel. If the
* secured tag is specified, it will always determine propagation behaviour.
* default propagation is specified with a secure-channels tag, that will be
* applied in the absence of a secured tag for the channel. If the secured tag
* is specified, it will always determine propagation behaviour.
*
* @author Jonas Partner
*/
public class SecurityPropagatingBeanPostProcessor implements BeanPostProcessor, Ordered {
protected static final String SECURITY_PROPAGATING_BEAN_POST_PROCESSOR_NAME = SecurityPropagatingBeanPostProcessor.class.getName();
protected static final String SECURITY_PROPAGATING_BEAN_POST_PROCESSOR_NAME = SecurityPropagatingBeanPostProcessor.class
.getName();
private final SecurityContextPropagatingChannelInterceptor interceptor =
new SecurityContextPropagatingChannelInterceptor();
private final SecurityContextPropagatingChannelInterceptor interceptor = new SecurityContextPropagatingChannelInterceptor();
private boolean propagateByDefault;
private final Log logger = LogFactory.getLog(this.getClass());
private List<String> channelsToInclude = new ArrayList<String>();
private List<String> channelsToExclude = new ArrayList<String>();
private List<Pattern> channelsToInclude = new ArrayList<Pattern>();
private List<Pattern> channelsToExclude = new ArrayList<Pattern>();
public boolean isPropagateByDefault() {
return this.propagateByDefault;
@@ -61,19 +59,19 @@ public class SecurityPropagatingBeanPostProcessor implements BeanPostProcessor,
this.propagateByDefault = propagateByDefault;
}
public List<String> getChannelsToInclude() {
public List<Pattern> getChannelsToInclude() {
return this.channelsToInclude;
}
public void setChannelsToInclude(List<String> channelsToInclude) {
public void setChannelsToInclude(List<Pattern> channelsToInclude) {
this.channelsToInclude = channelsToInclude;
}
public List<String> getChannelsToExclude() {
public List<Pattern> getChannelsToExclude() {
return this.channelsToExclude;
}
public void setChannelsToExclude(List<String> channelsToExclude) {
public void setChannelsToExclude(List<Pattern> channelsToExclude) {
this.channelsToExclude = channelsToExclude;
}
@@ -88,8 +86,7 @@ public class SecurityPropagatingBeanPostProcessor implements BeanPostProcessor,
public Object postProcessAfterInitialization(Object bean, String beanName) throws BeansException {
if (AbstractMessageChannel.class.isAssignableFrom(bean.getClass())) {
AbstractMessageChannel channel = (AbstractMessageChannel) bean;
if(this.channelsToInclude.contains(beanName) ||
(this.propagateByDefault && !this.channelsToExclude.contains(beanName))) {
if (isIncluded(beanName) || (this.propagateByDefault && !isExcluded(beanName))) {
channel.addInterceptor(this.interceptor);
if (logger.isDebugEnabled()) {
logger.debug("Channel '" + beanName + "' will propagate a SecurityContext.");
@@ -102,4 +99,21 @@ public class SecurityPropagatingBeanPostProcessor implements BeanPostProcessor,
return bean;
}
protected boolean isExcluded(String str) {
return matchesOnePattern(channelsToExclude, str);
}
protected boolean isIncluded(String str) {
return matchesOnePattern(channelsToInclude, str);
}
protected boolean matchesOnePattern(List<Pattern> patterns, String str) {
for (Pattern pattern : patterns) {
if (pattern.matcher(str).matches()) {
return true;
}
}
return false;
}
}

View File

@@ -41,10 +41,10 @@ public class SecurityPropagatingBeanPostProcessorDefinitionHelper {
private static final String PROPAGATE_BY_DEFAULT = "propagateByDefault";
public static void setPropagationDefault(boolean valueForPropagationDefault, ParserContext context) {
BeanDefinition beanDefintion = getOrCreateSecurityPropagatingBeanPostProcessor(context);
beanDefintion.getPropertyValues().addPropertyValue(PROPAGATE_BY_DEFAULT, Boolean.valueOf(valueForPropagationDefault));
beanDefintion.getPropertyValues().addPropertyValue(PROPAGATE_BY_DEFAULT,
Boolean.valueOf(valueForPropagationDefault));
}
@SuppressWarnings("unchecked")
@@ -52,7 +52,8 @@ public class SecurityPropagatingBeanPostProcessorDefinitionHelper {
BeanDefinition beanDefintion = getOrCreateSecurityPropagatingBeanPostProcessor(context);
List channelsToExclude;
if (beanDefintion.getPropertyValues().contains(CHANNELS_TO_EXCLUDE)) {
channelsToExclude = (List) beanDefintion.getPropertyValues().getPropertyValue(CHANNELS_TO_EXCLUDE).getValue();
channelsToExclude = (List) beanDefintion.getPropertyValues().getPropertyValue(CHANNELS_TO_EXCLUDE)
.getValue();
}
else {
channelsToExclude = new ArrayList<RuntimeBeanNameReference>();
@@ -62,15 +63,16 @@ public class SecurityPropagatingBeanPostProcessorDefinitionHelper {
}
@SuppressWarnings("unchecked")
public static void addToIncludeChannelList(String channelName, ParserContext context){
public static void addToIncludeChannelList(String channelName, ParserContext context) {
BeanDefinition beanDefintion = getOrCreateSecurityPropagatingBeanPostProcessor(context);
List channelsToExclude;
if (beanDefintion.getPropertyValues().contains(CHANNELS_TO_INCLUDE)) {
channelsToExclude = (List) beanDefintion.getPropertyValues().getPropertyValue(CHANNELS_TO_INCLUDE).getValue();
channelsToExclude = (List) beanDefintion.getPropertyValues().getPropertyValue(CHANNELS_TO_INCLUDE)
.getValue();
}
else {
channelsToExclude = new ArrayList<RuntimeBeanNameReference>();
beanDefintion.getPropertyValues().addPropertyValue(CHANNELS_TO_INCLUDE,channelsToExclude);
beanDefintion.getPropertyValues().addPropertyValue(CHANNELS_TO_INCLUDE, channelsToExclude);
}
channelsToExclude.add(channelName);
}

View File

@@ -0,0 +1,56 @@
/*
* Copyright 2002-2008 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.integration.security.config;
import org.w3c.dom.Element;
import org.springframework.beans.factory.BeanDefinitionStoreException;
import org.springframework.beans.factory.support.AbstractBeanDefinition;
import org.springframework.beans.factory.support.BeanDefinitionBuilder;
import org.springframework.beans.factory.xml.AbstractSingleBeanDefinitionParser;
import org.springframework.beans.factory.xml.ParserContext;
import org.springframework.security.context.SecurityContext;
import org.springframework.util.StringUtils;
/**
* Interprets the &lt;secure-channels&gt; element which controls default
* {@link SecurityContext} propagation behaviour.
*
* @author Jonas Partner
*/
public class SecurityPropagatingChannelsParser extends AbstractSingleBeanDefinitionParser {
@Override
protected void doParse(Element element, ParserContext parserContext, BeanDefinitionBuilder builder) {
builder.getBeanDefinition().setAbstract(true);
String propagation = element.getAttribute("propagate");
boolean propagateByDefault = true;
if (StringUtils.hasText(propagation)) {
propagateByDefault = Boolean.parseBoolean(propagation);
}
if (propagateByDefault) {
SecurityPropagatingBeanPostProcessorDefinitionHelper.setPropagationDefault(true, parserContext);
}
}
@Override
protected String resolveId(Element element, AbstractBeanDefinition definition, ParserContext parserContext)
throws BeanDefinitionStoreException {
return "internal.integration.SecureChannels";
}
}

View File

@@ -0,0 +1,62 @@
<?xml version="1.0" encoding="UTF-8"?>
<xsd:schema xmlns="http://www.springframework.org/schema/integration-security"
xmlns:xsd="http://www.w3.org/2001/XMLSchema"
xmlns:beans="http://www.springframework.org/schema/beans"
xmlns:tool="http://www.springframework.org/schema/tool"
targetNamespace="http://www.springframework.org/schema/integration-security"
elementFormDefault="qualified" attributeFormDefault="unqualified">
<xsd:import namespace="http://www.springframework.org/schema/beans" />
<xsd:import namespace="http://www.springframework.org/schema/tool" />
<xsd:element name="secured-channels">
<xsd:complexType>
<xsd:annotation>
<xsd:documentation>
Defines security requirements for one or more
message channels
</xsd:documentation>
</xsd:annotation>
<xsd:sequence>
<xsd:element name="channel-name-pattern" type="xsd:string" minOccurs="1" maxOccurs="unbounded"/>
</xsd:sequence>
<xsd:attribute name="receive-access" type="xsd:string" />
<xsd:attribute name="send-access" type="xsd:string" />
<xsd:attribute name="access-decision-manager" type="xsd:string" default="accessDecisionManager"/>
<xsd:attribute name="propagate" type="xsd:boolean" default="true" />
</xsd:complexType>
</xsd:element>
<xsd:element name="secured-targets">
<xsd:complexType>
<xsd:annotation>
<xsd:documentation>
Defines security requirements for one or more
Targets
</xsd:documentation>
</xsd:annotation>
<xsd:sequence>
<xsd:element name="targetNamePattern" type="xsd:string" />
</xsd:sequence>
<xsd:attribute name="access" type="xsd:string" />
<xsd:attribute name="access-decision-manager"
type="xsd:string" default="accessDecisionManager" />
</xsd:complexType>
</xsd:element>
<xsd:element name="security-propagating-channels">
<xsd:complexType>
<xsd:annotation>
<xsd:documentation>
Defines a bean post processor which propagates the
security context.
</xsd:documentation>
</xsd:annotation>
<xsd:attribute name="propagate" type="xsd:boolean" default="true" />
</xsd:complexType>
</xsd:element>
</xsd:schema>

View File

@@ -1,2 +0,0 @@
secured=org.springframework.integration.security.config.SecuredParser
secure-channels=org.springframework.integration.security.config.SecureChannelsParser

View File

@@ -0,0 +1 @@
http\://www.springframework.org/schema/integration-security=org.springframework.integration.security.config.IntegrationSecurityNamespaceHandler

View File

@@ -0,0 +1 @@
http\://www.springframework.org/schema/integration/spring-integration-security-1.0.xsd=org/springframework/integration/security/config/spring-integration-security-1.0.xsd