Fix for LDAP-64: AcegiAuthenticationSource does not support Anonymous Authentication
This commit is contained in:
@@ -18,12 +18,12 @@ package org.springframework.ldap.authentication;
|
|||||||
|
|
||||||
import org.acegisecurity.Authentication;
|
import org.acegisecurity.Authentication;
|
||||||
import org.acegisecurity.context.SecurityContextHolder;
|
import org.acegisecurity.context.SecurityContextHolder;
|
||||||
|
import org.acegisecurity.providers.anonymous.AnonymousAuthenticationToken;
|
||||||
import org.acegisecurity.userdetails.ldap.LdapUserDetails;
|
import org.acegisecurity.userdetails.ldap.LdapUserDetails;
|
||||||
import org.apache.commons.logging.Log;
|
import org.apache.commons.logging.Log;
|
||||||
import org.apache.commons.logging.LogFactory;
|
import org.apache.commons.logging.LogFactory;
|
||||||
import org.springframework.ldap.core.AuthenticationSource;
|
import org.springframework.ldap.core.AuthenticationSource;
|
||||||
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* An AuthenticationSource to retrieve authentication information stored in
|
* An AuthenticationSource to retrieve authentication information stored in
|
||||||
* Acegi's SecurityContextHolder. Use Acegi's LdapAuthenticationProvider have a
|
* Acegi's SecurityContextHolder. Use Acegi's LdapAuthenticationProvider have a
|
||||||
@@ -47,13 +47,19 @@ public class AcegiAuthenticationSource implements AuthenticationSource {
|
|||||||
.getAuthentication();
|
.getAuthentication();
|
||||||
if (authentication != null) {
|
if (authentication != null) {
|
||||||
Object principal = authentication.getPrincipal();
|
Object principal = authentication.getPrincipal();
|
||||||
if (!(principal instanceof LdapUserDetails)) {
|
if (principal instanceof LdapUserDetails) {
|
||||||
|
LdapUserDetails details = (LdapUserDetails) principal;
|
||||||
|
return details.getDn();
|
||||||
|
} else if (authentication instanceof AnonymousAuthenticationToken) {
|
||||||
|
if (log.isDebugEnabled()) {
|
||||||
|
log
|
||||||
|
.debug("Anonymous Authentication, returning empty String as Principal");
|
||||||
|
}
|
||||||
|
return "";
|
||||||
|
} else {
|
||||||
throw new IllegalArgumentException(
|
throw new IllegalArgumentException(
|
||||||
"The principal property of the authentication object -"
|
"The principal property of the authentication object -"
|
||||||
+ "needs to be a LdapUserDetails.");
|
+ "needs to be a LdapUserDetails.");
|
||||||
} else {
|
|
||||||
LdapUserDetails details = (LdapUserDetails) principal;
|
|
||||||
return details.getDn();
|
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
log.warn("No Authentication object set in SecurityContext - "
|
log.warn("No Authentication object set in SecurityContext - "
|
||||||
|
|||||||
@@ -18,10 +18,10 @@ package org.springframework.ldap.authentication;
|
|||||||
|
|
||||||
import junit.framework.TestCase;
|
import junit.framework.TestCase;
|
||||||
|
|
||||||
|
|
||||||
import org.acegisecurity.Authentication;
|
import org.acegisecurity.Authentication;
|
||||||
import org.acegisecurity.GrantedAuthority;
|
import org.acegisecurity.GrantedAuthority;
|
||||||
import org.acegisecurity.context.SecurityContextHolder;
|
import org.acegisecurity.context.SecurityContextHolder;
|
||||||
|
import org.acegisecurity.providers.anonymous.AnonymousAuthenticationToken;
|
||||||
import org.acegisecurity.userdetails.User;
|
import org.acegisecurity.userdetails.User;
|
||||||
import org.acegisecurity.userdetails.ldap.LdapUserDetails;
|
import org.acegisecurity.userdetails.ldap.LdapUserDetails;
|
||||||
import org.easymock.MockControl;
|
import org.easymock.MockControl;
|
||||||
@@ -83,7 +83,7 @@ public class AcegiAuthenticationSourceTest extends TestCase {
|
|||||||
|
|
||||||
ldapUserDetailsControl.expectAndDefaultReturn(ldapUserDetailsMock
|
ldapUserDetailsControl.expectAndDefaultReturn(ldapUserDetailsMock
|
||||||
.getDn(), "cn=Manager");
|
.getDn(), "cn=Manager");
|
||||||
|
|
||||||
SecurityContextHolder.getContext()
|
SecurityContextHolder.getContext()
|
||||||
.setAuthentication(authenticationMock);
|
.setAuthentication(authenticationMock);
|
||||||
|
|
||||||
@@ -126,4 +126,19 @@ public class AcegiAuthenticationSourceTest extends TestCase {
|
|||||||
}
|
}
|
||||||
verify();
|
verify();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public void testGetPrincipalWithAnonymousAuthenticationToken() {
|
||||||
|
|
||||||
|
SecurityContextHolder.getContext().setAuthentication(
|
||||||
|
new AnonymousAuthenticationToken("dummy", "dummy",
|
||||||
|
new GrantedAuthority[] { new DummyAuthoroty() }));
|
||||||
|
|
||||||
|
assertEquals("", tested.getPrincipal());
|
||||||
|
}
|
||||||
|
|
||||||
|
private static class DummyAuthoroty implements GrantedAuthority {
|
||||||
|
public String getAuthority() {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user