Added ChannelSecurityInterceptor as a replacement for SecurityEnforcingChannelInterceptor. It is a subclass of AbstractSecurityInterceptor. Also added the ChannelInvocationDefinitionSource, ChannelInvocation (the secured object), and ChannelAccessPolicy.
This commit is contained in:
@@ -0,0 +1,62 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security.channel;
|
||||
|
||||
import org.springframework.security.ConfigAttributeDefinition;
|
||||
import org.springframework.util.Assert;
|
||||
import org.springframework.util.StringUtils;
|
||||
|
||||
/**
|
||||
* Creates the {@link ConfigAttributeDefinition}s for secured channel
|
||||
* send and receive operations based on simple String values.
|
||||
*/
|
||||
public class ChannelAccessPolicy {
|
||||
|
||||
private final ConfigAttributeDefinition configAttributeDefinitionForSend;
|
||||
|
||||
private final ConfigAttributeDefinition configAttributeDefinitionForReceive;
|
||||
|
||||
|
||||
/**
|
||||
* Create an access policy instance. The provided 'sendAccess' and 'receiveAccess'
|
||||
* values may be a single String or a comma-delimited list of values. All whitespace
|
||||
* will be trimmed. A <code>null</code> value indicates that the policy does not
|
||||
* apply for either send or receive access type. At most one of the values may be null.
|
||||
*/
|
||||
public ChannelAccessPolicy(String sendAccess, String receiveAccess) {
|
||||
Assert.isTrue(sendAccess != null || receiveAccess != null,
|
||||
"At least one of 'sendAccess' and 'receiveAccess' must not be null.");
|
||||
String[] sendValues = StringUtils.trimArrayElements(
|
||||
StringUtils.commaDelimitedListToStringArray(sendAccess));
|
||||
String[] receiveValues = StringUtils.trimArrayElements(
|
||||
StringUtils.commaDelimitedListToStringArray(receiveAccess));
|
||||
this.configAttributeDefinitionForSend = (sendValues.length > 0)
|
||||
? new ConfigAttributeDefinition(sendValues) : null;
|
||||
this.configAttributeDefinitionForReceive = (receiveValues.length > 0)
|
||||
? new ConfigAttributeDefinition(receiveValues) : null;
|
||||
}
|
||||
|
||||
|
||||
public ConfigAttributeDefinition getConfigAttributeDefinitionForSend() {
|
||||
return this.configAttributeDefinitionForSend;
|
||||
}
|
||||
|
||||
public ConfigAttributeDefinition getConfigAttributeDefinitionForReceive() {
|
||||
return this.configAttributeDefinitionForReceive;
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,83 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security.channel;
|
||||
|
||||
import org.aopalliance.intercept.MethodInvocation;
|
||||
|
||||
import org.springframework.integration.channel.MessageChannel;
|
||||
import org.springframework.integration.message.Message;
|
||||
import org.springframework.util.Assert;
|
||||
|
||||
/**
|
||||
* Secured object for {@link ChannelSecurityInterceptor}. Maintains a reference
|
||||
* to the original {@link MethodInvocation} instance and provides convenient
|
||||
* access to the secured {@link MessageChannel}. If the intercepted invocation
|
||||
* is a <em>send</em> operation, the {@link Message} is also available.
|
||||
*
|
||||
* @author Mark Fisher
|
||||
*/
|
||||
public class ChannelInvocation {
|
||||
|
||||
private final MessageChannel channel;
|
||||
|
||||
private final Message<?> message;
|
||||
|
||||
private final MethodInvocation methodInvocation;
|
||||
|
||||
|
||||
/**
|
||||
* @param methodInvocation the intercepted MethodInvocation instance
|
||||
*/
|
||||
public ChannelInvocation(MethodInvocation methodInvocation) {
|
||||
Assert.notNull(methodInvocation, "MethodInvocation must not be null");
|
||||
Assert.isAssignable(MessageChannel.class, methodInvocation.getThis().getClass(),
|
||||
"MethodInvocation must be on a MessageChannel");
|
||||
this.channel = (MessageChannel) methodInvocation.getThis();
|
||||
if (methodInvocation.getMethod().getName().equals("send")) {
|
||||
if (methodInvocation.getArguments().length < 1 || !(methodInvocation.getArguments()[0] instanceof Message)) {
|
||||
throw new IllegalStateException("expected a Message as the first parameter of the channel's send method");
|
||||
}
|
||||
this.message = (Message<?>) methodInvocation.getArguments()[0];
|
||||
}
|
||||
else {
|
||||
this.message = null;
|
||||
}
|
||||
this.methodInvocation = methodInvocation;
|
||||
}
|
||||
|
||||
|
||||
public MessageChannel getChannel() {
|
||||
return this.channel;
|
||||
}
|
||||
|
||||
public Message<?> getMessage() {
|
||||
return this.message;
|
||||
}
|
||||
|
||||
public MethodInvocation getMethodInvocation() {
|
||||
return this.methodInvocation;
|
||||
}
|
||||
|
||||
public boolean isSend() {
|
||||
return "send".equals(this.methodInvocation.getMethod().getName());
|
||||
}
|
||||
|
||||
public boolean isReceive() {
|
||||
return "receive".equals(this.methodInvocation.getMethod().getName());
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,100 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security.channel;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.Collection;
|
||||
import java.util.HashSet;
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import java.util.Set;
|
||||
import java.util.regex.Pattern;
|
||||
|
||||
import org.springframework.integration.channel.MessageChannel;
|
||||
import org.springframework.security.ConfigAttribute;
|
||||
import org.springframework.security.ConfigAttributeDefinition;
|
||||
import org.springframework.security.intercept.ObjectDefinitionSource;
|
||||
import org.springframework.util.Assert;
|
||||
|
||||
/**
|
||||
* The {@link ObjectDefinitionSource} implementation for secured {@link MessageChannel}s.
|
||||
*
|
||||
* @author Mark Fisher
|
||||
*/
|
||||
public class ChannelInvocationDefinitionSource implements ObjectDefinitionSource {
|
||||
|
||||
private final Map<Pattern, ChannelAccessPolicy> patternMappings =
|
||||
new LinkedHashMap<Pattern, ChannelAccessPolicy>();
|
||||
|
||||
|
||||
public void addPatternMapping(Pattern pattern, ChannelAccessPolicy accessPolicy) {
|
||||
this.patternMappings.put(pattern, accessPolicy);
|
||||
}
|
||||
|
||||
public Set<Pattern> getPatterns() {
|
||||
return this.patternMappings.keySet();
|
||||
}
|
||||
|
||||
@SuppressWarnings("unchecked")
|
||||
public boolean supports(Class clazz) {
|
||||
return ChannelInvocation.class.isAssignableFrom(clazz);
|
||||
}
|
||||
|
||||
@SuppressWarnings("unchecked")
|
||||
public ConfigAttributeDefinition getAttributes(Object object) throws IllegalArgumentException {
|
||||
Assert.isAssignable(ChannelInvocation.class, object.getClass());
|
||||
ChannelInvocation invocation = (ChannelInvocation) object;
|
||||
String channelName = invocation.getChannel().getName();
|
||||
List<ConfigAttribute> attributes = new ArrayList<ConfigAttribute>();
|
||||
for (Map.Entry<Pattern, ChannelAccessPolicy> mapping : this.patternMappings.entrySet()) {
|
||||
Pattern pattern = mapping.getKey();
|
||||
ChannelAccessPolicy accessPolicy = mapping.getValue();
|
||||
if (pattern.matcher(channelName).matches()) {
|
||||
if (invocation.isSend()) {
|
||||
ConfigAttributeDefinition definition = accessPolicy.getConfigAttributeDefinitionForSend();
|
||||
if (definition != null) {
|
||||
attributes.addAll(definition.getConfigAttributes());
|
||||
}
|
||||
}
|
||||
else if (invocation.isReceive()) {
|
||||
ConfigAttributeDefinition definition = accessPolicy.getConfigAttributeDefinitionForReceive();
|
||||
if (definition != null) {
|
||||
attributes.addAll(definition.getConfigAttributes());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return new ConfigAttributeDefinition(attributes);
|
||||
}
|
||||
|
||||
public Collection<?> getConfigAttributeDefinitions() {
|
||||
Set<ConfigAttributeDefinition> definitions = new HashSet<ConfigAttributeDefinition>();
|
||||
for (ChannelAccessPolicy accessPolicy : this.patternMappings.values()) {
|
||||
ConfigAttributeDefinition sendDefinition = accessPolicy.getConfigAttributeDefinitionForSend();
|
||||
if (sendDefinition != null) {
|
||||
definitions.add(sendDefinition);
|
||||
}
|
||||
ConfigAttributeDefinition receiveDefinition = accessPolicy.getConfigAttributeDefinitionForReceive();
|
||||
if (receiveDefinition != null) {
|
||||
definitions.add(receiveDefinition);
|
||||
}
|
||||
}
|
||||
return definitions;
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,75 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security.channel;
|
||||
|
||||
import java.lang.reflect.Method;
|
||||
|
||||
import org.aopalliance.intercept.MethodInterceptor;
|
||||
import org.aopalliance.intercept.MethodInvocation;
|
||||
|
||||
import org.springframework.security.intercept.AbstractSecurityInterceptor;
|
||||
import org.springframework.security.intercept.InterceptorStatusToken;
|
||||
import org.springframework.security.intercept.ObjectDefinitionSource;
|
||||
import org.springframework.util.Assert;
|
||||
|
||||
/**
|
||||
* An AOP interceptor that enforces authorization for MessageChannel send and/or receive calls.
|
||||
*
|
||||
* @author Mark Fisher
|
||||
*/
|
||||
public class ChannelSecurityInterceptor extends AbstractSecurityInterceptor implements MethodInterceptor {
|
||||
|
||||
private final ChannelInvocationDefinitionSource objectDefinitionSource;
|
||||
|
||||
|
||||
public ChannelSecurityInterceptor(ChannelInvocationDefinitionSource objectDefinitionSource) {
|
||||
Assert.notNull(objectDefinitionSource, "objectDefinitionSource must not be null");
|
||||
this.objectDefinitionSource = objectDefinitionSource;
|
||||
}
|
||||
|
||||
|
||||
@Override
|
||||
public Class<?> getSecureObjectClass() {
|
||||
return ChannelInvocation.class;
|
||||
}
|
||||
|
||||
@Override
|
||||
public ObjectDefinitionSource obtainObjectDefinitionSource() {
|
||||
return this.objectDefinitionSource;
|
||||
}
|
||||
|
||||
public Object invoke(MethodInvocation invocation) throws Throwable {
|
||||
Method method = invocation.getMethod();
|
||||
if (method.getName().equals("send") || method.getName().equals("receive")) {
|
||||
return this.invokeWithAuthorizationCheck(invocation);
|
||||
}
|
||||
return invocation.proceed();
|
||||
}
|
||||
|
||||
private Object invokeWithAuthorizationCheck(MethodInvocation methodInvocation) throws Throwable {
|
||||
Object returnValue = null;
|
||||
InterceptorStatusToken token = super.beforeInvocation(new ChannelInvocation(methodInvocation));
|
||||
try {
|
||||
returnValue = methodInvocation.proceed();
|
||||
}
|
||||
finally {
|
||||
returnValue = super.afterInvocation(token, returnValue);
|
||||
}
|
||||
return returnValue;
|
||||
}
|
||||
|
||||
}
|
||||
@@ -1,98 +0,0 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security.channel;
|
||||
|
||||
import org.springframework.integration.channel.MessageChannel;
|
||||
import org.springframework.integration.channel.interceptor.ChannelInterceptorAdapter;
|
||||
import org.springframework.integration.message.Message;
|
||||
import org.springframework.security.AccessDecisionManager;
|
||||
import org.springframework.security.Authentication;
|
||||
import org.springframework.security.AuthenticationCredentialsNotFoundException;
|
||||
import org.springframework.security.ConfigAttributeDefinition;
|
||||
import org.springframework.security.context.SecurityContextHolder;
|
||||
import org.springframework.util.Assert;
|
||||
|
||||
/**
|
||||
* Delegates to the provided instance of {@link AccessDecisionManager} to
|
||||
* enforce the security on the send and receive calls of the {@link MessageChannel}.
|
||||
*
|
||||
* @author Jonas Partner
|
||||
* @author Mark Fisher
|
||||
*/
|
||||
public class SecurityEnforcingChannelInterceptor extends ChannelInterceptorAdapter {
|
||||
|
||||
private final AccessDecisionManager accessDecisionManger;
|
||||
|
||||
private volatile ConfigAttributeDefinition sendSecurityAttributes;
|
||||
|
||||
private volatile ConfigAttributeDefinition receiveSecurityAttributes;
|
||||
|
||||
|
||||
public SecurityEnforcingChannelInterceptor(AccessDecisionManager accessDecisionManager) {
|
||||
Assert.notNull(accessDecisionManager, "AccessDecisionManager must not be null");
|
||||
this.accessDecisionManger = accessDecisionManager;
|
||||
}
|
||||
|
||||
|
||||
public ConfigAttributeDefinition getSendSecurityAttributes() {
|
||||
return this.sendSecurityAttributes;
|
||||
}
|
||||
|
||||
public void setSendSecurityAttributes(ConfigAttributeDefinition sendSecurityAttributes) {
|
||||
this.sendSecurityAttributes = sendSecurityAttributes;
|
||||
}
|
||||
|
||||
public ConfigAttributeDefinition getReceiveSecurityAttributes() {
|
||||
return this.receiveSecurityAttributes;
|
||||
}
|
||||
|
||||
public void setReceiveSecurityAttributes(ConfigAttributeDefinition receiveSecurityAttributes) {
|
||||
this.receiveSecurityAttributes = receiveSecurityAttributes;
|
||||
}
|
||||
|
||||
@Override
|
||||
public Message<?> preSend(Message<?> message, MessageChannel channel) {
|
||||
this.checkSend(channel);
|
||||
return message;
|
||||
}
|
||||
|
||||
@Override
|
||||
public boolean preReceive(MessageChannel channel) {
|
||||
this.checkReceive(channel);
|
||||
return super.preReceive(channel);
|
||||
}
|
||||
|
||||
private void checkSend(MessageChannel channel) {
|
||||
this.checkPermission(channel, this.sendSecurityAttributes);
|
||||
}
|
||||
|
||||
private void checkReceive(MessageChannel channel) {
|
||||
this.checkPermission(channel, this.receiveSecurityAttributes);
|
||||
}
|
||||
|
||||
private void checkPermission(MessageChannel messageChannel, ConfigAttributeDefinition securityAttributes) {
|
||||
if (securityAttributes != null) {
|
||||
Authentication authentication = SecurityContextHolder.getContext().getAuthentication();
|
||||
if (authentication == null) {
|
||||
throw new AuthenticationCredentialsNotFoundException(
|
||||
"No Authentication object available. Consider enabling the SecurityPropagatingBeanPostProcessor.");
|
||||
}
|
||||
this.accessDecisionManger.decide(authentication, messageChannel, securityAttributes);
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,72 @@
|
||||
/*
|
||||
* Copyright 2002-2008 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.integration.security.config;
|
||||
|
||||
import java.util.Set;
|
||||
import java.util.regex.Pattern;
|
||||
|
||||
import org.springframework.aop.framework.ProxyFactory;
|
||||
import org.springframework.aop.support.DefaultPointcutAdvisor;
|
||||
import org.springframework.beans.BeansException;
|
||||
import org.springframework.beans.factory.config.BeanPostProcessor;
|
||||
import org.springframework.integration.channel.MessageChannel;
|
||||
import org.springframework.integration.security.channel.ChannelInvocationDefinitionSource;
|
||||
import org.springframework.integration.security.channel.ChannelSecurityInterceptor;
|
||||
import org.springframework.util.Assert;
|
||||
|
||||
/**
|
||||
* A {@link BeanPostProcessor} that proxies {@link MessageChannel}s to apply a {@link ChannelSecurityInterceptor}.
|
||||
*
|
||||
* @author Mark Fisher
|
||||
*/
|
||||
public class ChannelSecurityInterceptorBeanPostProcessor implements BeanPostProcessor {
|
||||
|
||||
private final ChannelSecurityInterceptor interceptor;
|
||||
|
||||
|
||||
public ChannelSecurityInterceptorBeanPostProcessor(ChannelSecurityInterceptor interceptor) {
|
||||
Assert.notNull(interceptor, "interceptor must not be null");
|
||||
this.interceptor = interceptor;
|
||||
}
|
||||
|
||||
|
||||
public Object postProcessBeforeInitialization(Object bean, String beanName) throws BeansException {
|
||||
return bean;
|
||||
}
|
||||
|
||||
public Object postProcessAfterInitialization(Object bean, String beanName) throws BeansException {
|
||||
if (bean instanceof MessageChannel && shouldProxy((MessageChannel) bean,
|
||||
(ChannelInvocationDefinitionSource) this.interceptor.obtainObjectDefinitionSource())) {
|
||||
ProxyFactory proxyFactory = new ProxyFactory(bean);
|
||||
proxyFactory.addAdvisor(new DefaultPointcutAdvisor(this.interceptor));
|
||||
return proxyFactory.getProxy();
|
||||
}
|
||||
return bean;
|
||||
}
|
||||
|
||||
private boolean shouldProxy(MessageChannel channel, ChannelInvocationDefinitionSource definitionSource) {
|
||||
Assert.notNull(channel.getName(), "channel name must not be null");
|
||||
Set<Pattern> patterns = ((ChannelInvocationDefinitionSource) this.interceptor.obtainObjectDefinitionSource()).getPatterns();
|
||||
for (Pattern pattern : patterns) {
|
||||
if (pattern.matcher(channel.getName()).matches()) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
}
|
||||
@@ -16,34 +16,37 @@
|
||||
|
||||
package org.springframework.integration.security.config;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
import java.util.regex.Pattern;
|
||||
|
||||
import org.w3c.dom.Element;
|
||||
|
||||
import org.springframework.beans.factory.config.BeanDefinition;
|
||||
import org.springframework.beans.factory.config.ConstructorArgumentValues.ValueHolder;
|
||||
import org.springframework.beans.factory.support.BeanDefinitionBuilder;
|
||||
import org.springframework.beans.factory.support.BeanDefinitionReaderUtils;
|
||||
import org.springframework.beans.factory.xml.AbstractSingleBeanDefinitionParser;
|
||||
import org.springframework.beans.factory.xml.ParserContext;
|
||||
import org.springframework.integration.security.ChannelInterceptorRegisteringBeanPostProcessor;
|
||||
import org.springframework.integration.security.channel.SecurityEnforcingChannelInterceptor;
|
||||
import org.springframework.security.ConfigAttributeDefinition;
|
||||
import org.springframework.security.context.SecurityContext;
|
||||
import org.springframework.integration.ConfigurationException;
|
||||
import org.springframework.integration.channel.MessageChannel;
|
||||
import org.springframework.integration.config.IntegrationNamespaceUtils;
|
||||
import org.springframework.integration.security.channel.ChannelAccessPolicy;
|
||||
import org.springframework.integration.security.channel.ChannelInvocationDefinitionSource;
|
||||
import org.springframework.integration.security.channel.ChannelSecurityInterceptor;
|
||||
import org.springframework.util.StringUtils;
|
||||
import org.w3c.dom.Element;
|
||||
import org.w3c.dom.NodeList;
|
||||
import org.springframework.util.xml.DomUtils;
|
||||
|
||||
/**
|
||||
* Determines {@link SecurityContext} propagation behaviour for the parent
|
||||
* element channel, and creates a {@link SecurityEnforcingChannelInterceptor} to
|
||||
* control send and receive access if send-access and/or receive-access is
|
||||
* specified.
|
||||
* Creates a {@link ChannelSecurityInterceptor} to control send and receive access,
|
||||
* and creates a {@link ChannelSecurityInterceptorBeanPostProcessor} to apply the
|
||||
* interceptor to {@link MessageChannel}s whose names match the specified patterns.
|
||||
*
|
||||
* @author Jonas Partner
|
||||
* @author Mark Fisher
|
||||
*/
|
||||
public class SecuredChannelsParser extends AbstractSingleBeanDefinitionParser {
|
||||
|
||||
public SecuredChannelsParser() {
|
||||
super();
|
||||
@Override
|
||||
protected Class<?> getBeanClass(Element element) {
|
||||
return ChannelSecurityInterceptorBeanPostProcessor.class;
|
||||
}
|
||||
|
||||
@Override
|
||||
@@ -51,61 +54,33 @@ public class SecuredChannelsParser extends AbstractSingleBeanDefinitionParser {
|
||||
return true;
|
||||
}
|
||||
|
||||
@Override
|
||||
protected boolean shouldGenerateIdAsFallback() {
|
||||
return true;
|
||||
}
|
||||
|
||||
@Override
|
||||
protected void doParse(Element element, ParserContext parserContext, BeanDefinitionBuilder builder) {
|
||||
String receiveAccess = element.getAttribute("receive-access");
|
||||
String sendAccess = element.getAttribute("send-access");
|
||||
String accessDecisionManager = element.getAttribute("access-decision-manager");
|
||||
|
||||
BeanDefinition interceptorBeanDefinition = createSecurityEnforcingChannelInterceptor(accessDecisionManager,
|
||||
sendAccess, receiveAccess);
|
||||
|
||||
List<String> patternList = processPatterns(element.getElementsByTagNameNS(element.getNamespaceURI(),
|
||||
"channel-name-pattern"));
|
||||
|
||||
builder.getBeanDefinition().setBeanClass(ChannelInterceptorRegisteringBeanPostProcessor.class);
|
||||
builder.getBeanDefinition().getConstructorArgumentValues().addGenericArgumentValue(
|
||||
new ValueHolder(interceptorBeanDefinition));
|
||||
builder.getBeanDefinition().getConstructorArgumentValues()
|
||||
.addGenericArgumentValue(new ValueHolder(patternList));
|
||||
|
||||
ChannelInvocationDefinitionSource objectDefinitionSource = this.parseObjectDefinitionSource(element);
|
||||
BeanDefinitionBuilder interceptorBuilder = BeanDefinitionBuilder.genericBeanDefinition(ChannelSecurityInterceptor.class);
|
||||
interceptorBuilder.addConstructorArgValue(objectDefinitionSource);
|
||||
IntegrationNamespaceUtils.setReferenceIfAttributeDefined(interceptorBuilder, element, "authentication-manager");
|
||||
IntegrationNamespaceUtils.setReferenceIfAttributeDefined(interceptorBuilder, element, "access-decision-manager");
|
||||
String interceptorBeanName = BeanDefinitionReaderUtils.registerWithGeneratedName(
|
||||
interceptorBuilder.getBeanDefinition(), parserContext.getRegistry());
|
||||
builder.addConstructorArgReference(interceptorBeanName);
|
||||
}
|
||||
|
||||
protected List<String> processPatterns(NodeList patternList) {
|
||||
List<String> patterns = new ArrayList<String>();
|
||||
for (int i = 0; i < patternList.getLength(); i++) {
|
||||
Element patternElement = (Element) patternList.item(i);
|
||||
patterns.add(patternElement.getTextContent());
|
||||
}
|
||||
return patterns;
|
||||
}
|
||||
|
||||
protected BeanDefinition createSecurityEnforcingChannelInterceptor(String accessDecisionManager, String sendAccess,
|
||||
String receiveAccess) {
|
||||
if (!StringUtils.hasText(accessDecisionManager)) {
|
||||
accessDecisionManager = "accessDecisionManager";
|
||||
@SuppressWarnings("unchecked")
|
||||
private ChannelInvocationDefinitionSource parseObjectDefinitionSource(Element element) {
|
||||
ChannelInvocationDefinitionSource objectDefinitionSource = new ChannelInvocationDefinitionSource();
|
||||
List<Element> accessPolicyElements = (List<Element>) DomUtils.getChildElementsByTagName(element, "access-policy");
|
||||
for (Element accessPolicyElement : accessPolicyElements) {
|
||||
Pattern pattern = Pattern.compile(accessPolicyElement.getAttribute("pattern"));
|
||||
String sendAccess = accessPolicyElement.getAttribute("send-access");
|
||||
String receiveAccess = accessPolicyElement.getAttribute("receive-access");
|
||||
if (!StringUtils.hasText(sendAccess) && !StringUtils.hasText(receiveAccess)) {
|
||||
throw new ConfigurationException("At least one of 'send-access' or 'receive-access' must be provided.");
|
||||
}
|
||||
objectDefinitionSource.addPatternMapping(pattern, new ChannelAccessPolicy(sendAccess, receiveAccess));
|
||||
}
|
||||
BeanDefinitionBuilder beanDefinitionBuilder = BeanDefinitionBuilder
|
||||
.genericBeanDefinition(SecurityEnforcingChannelInterceptor.class);
|
||||
beanDefinitionBuilder.addConstructorArgReference(accessDecisionManager);
|
||||
|
||||
if (StringUtils.hasText(sendAccess)) {
|
||||
ConfigAttributeDefinition sendDefinition = new ConfigAttributeDefinition(StringUtils.tokenizeToStringArray(
|
||||
sendAccess, ","));
|
||||
beanDefinitionBuilder.addPropertyValue("sendSecurityAttributes", sendDefinition);
|
||||
}
|
||||
if (StringUtils.hasText(receiveAccess)) {
|
||||
ConfigAttributeDefinition receiveDefinition = new ConfigAttributeDefinition(StringUtils
|
||||
.tokenizeToStringArray(receiveAccess, ","));
|
||||
beanDefinitionBuilder.addPropertyValue("receiveSecurityAttributes", receiveDefinition);
|
||||
}
|
||||
return beanDefinitionBuilder.getBeanDefinition();
|
||||
|
||||
return objectDefinitionSource;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -1,10 +1,9 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
|
||||
<xsd:schema xmlns="http://www.springframework.org/schema/integration-security"
|
||||
<xsd:schema xmlns="http://www.springframework.org/schema/integration/security"
|
||||
xmlns:xsd="http://www.w3.org/2001/XMLSchema"
|
||||
xmlns:beans="http://www.springframework.org/schema/beans"
|
||||
xmlns:tool="http://www.springframework.org/schema/tool"
|
||||
targetNamespace="http://www.springframework.org/schema/integration-security"
|
||||
targetNamespace="http://www.springframework.org/schema/integration/security"
|
||||
elementFormDefault="qualified" attributeFormDefault="unqualified">
|
||||
|
||||
<xsd:import namespace="http://www.springframework.org/schema/beans" />
|
||||
@@ -18,14 +17,24 @@
|
||||
</xsd:documentation>
|
||||
</xsd:annotation>
|
||||
<xsd:sequence>
|
||||
<xsd:element name="channel-name-pattern" type="xsd:string" minOccurs="1" maxOccurs="unbounded"/>
|
||||
<xsd:element name="access-policy" type="accessPolicyType" minOccurs="1" maxOccurs="unbounded"/>
|
||||
</xsd:sequence>
|
||||
<xsd:attribute name="send-access" type="xsd:string"/>
|
||||
<xsd:attribute name="receive-access" type="xsd:string"/>
|
||||
<xsd:attribute name="authentication-manager" type="xsd:string" default="authenticationManager"/>
|
||||
<xsd:attribute name="access-decision-manager" type="xsd:string" default="accessDecisionManager"/>
|
||||
</xsd:complexType>
|
||||
</xsd:element>
|
||||
|
||||
<xsd:complexType name="accessPolicyType">
|
||||
<xsd:annotation>
|
||||
<xsd:documentation>
|
||||
Defines the security access policy for send and/or receive invocations based on a Message Channel name pattern.
|
||||
</xsd:documentation>
|
||||
</xsd:annotation>
|
||||
<xsd:attribute name="pattern" type="xsd:string" use="required"/>
|
||||
<xsd:attribute name="send-access" type="xsd:string"/>
|
||||
<xsd:attribute name="receive-access" type="xsd:string"/>
|
||||
</xsd:complexType>
|
||||
|
||||
<xsd:element name="endpoint-security-policy">
|
||||
<xsd:complexType>
|
||||
<xsd:annotation>
|
||||
|
||||
@@ -1 +1 @@
|
||||
http\://www.springframework.org/schema/integration-security=org.springframework.integration.security.config.IntegrationSecurityNamespaceHandler
|
||||
http\://www.springframework.org/schema/integration/security=org.springframework.integration.security.config.IntegrationSecurityNamespaceHandler
|
||||
Reference in New Issue
Block a user