SEC-2676: Add SpEL Spring Security Integration
This commit is contained in:
@@ -0,0 +1,73 @@
|
||||
/*
|
||||
* Copyright 2002-2014 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License"); you may not
|
||||
* use this file except in compliance with the License. You may obtain a copy of
|
||||
* the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
|
||||
* WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
|
||||
* License for the specific language governing permissions and limitations under
|
||||
* the License.
|
||||
*/
|
||||
package samples.data;
|
||||
|
||||
import org.junit.After;
|
||||
import org.junit.Before;
|
||||
import org.junit.Test;
|
||||
import org.junit.runner.RunWith;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.security.authentication.UsernamePasswordAuthenticationToken;
|
||||
import org.springframework.security.core.GrantedAuthority;
|
||||
import org.springframework.security.core.authority.AuthorityUtils;
|
||||
import org.springframework.security.core.context.SecurityContextHolder;
|
||||
import org.springframework.test.context.ContextConfiguration;
|
||||
import org.springframework.test.context.junit4.SpringJUnit4ClassRunner;
|
||||
import samples.DataConfig;
|
||||
|
||||
import java.util.List;
|
||||
|
||||
import static org.fest.assertions.Assertions.assertThat;
|
||||
|
||||
/**
|
||||
* @author Rob Winch
|
||||
*/
|
||||
@RunWith(SpringJUnit4ClassRunner.class)
|
||||
@ContextConfiguration(classes = DataConfig.class)
|
||||
public class SecurityMessageRepositoryTests {
|
||||
@Autowired
|
||||
SecurityMessageRepository repository;
|
||||
|
||||
User user;
|
||||
|
||||
@Before
|
||||
public void setup() {
|
||||
user = new User();
|
||||
user.setId(0L);
|
||||
List<GrantedAuthority> authorities =
|
||||
AuthorityUtils.createAuthorityList("ROLE_USER");
|
||||
UsernamePasswordAuthenticationToken authentication =
|
||||
new UsernamePasswordAuthenticationToken(user, "notused", authorities);
|
||||
SecurityContextHolder
|
||||
.getContext()
|
||||
.setAuthentication(authentication);
|
||||
}
|
||||
|
||||
@After
|
||||
public void cleanup() {
|
||||
SecurityContextHolder.clearContext();
|
||||
}
|
||||
|
||||
@Test
|
||||
public void findAllOnlyToCurrentUser() {
|
||||
Long expectedId = user.getId();
|
||||
List<Message> messages = repository.findAll();
|
||||
assertThat(messages.size()).isEqualTo(3);
|
||||
for(Message m : messages) {
|
||||
assertThat(m.getTo().getId()).isEqualTo(expectedId);
|
||||
}
|
||||
}
|
||||
}
|
||||
10
samples/data-jc/src/test/resources/data.sql
Normal file
10
samples/data-jc/src/test/resources/data.sql
Normal file
@@ -0,0 +1,10 @@
|
||||
insert into user(id,email,password,firstName,lastName) values (0,'rob@example.com','password','Rob','Winch');
|
||||
insert into user(id,email,password,firstName,lastName) values (1,'luke@example.com','password','Luke','Taylor');
|
||||
|
||||
insert into message(id,created,to_id,summary,text) values (100,'2014-07-10 10:00:00',0,'Hello Rob','This message is for Rob');
|
||||
insert into message(id,created,to_id,summary,text) values (101,'2014-07-10 14:00:00',0,'How are you Rob?','This message is for Rob');
|
||||
insert into message(id,created,to_id,summary,text) values (102,'2014-07-11 22:00:00',0,'Is this secure?','This message is for Rob');
|
||||
|
||||
insert into message(id,created,to_id,summary,text) values (110,'2014-07-12 10:00:00',1,'Hello Luke','This message is for Luke');
|
||||
insert into message(id,created,to_id,summary,text) values (111,'2014-07-12 10:00:00',1,'Greetings Luke','This message is for Luke');
|
||||
insert into message(id,created,to_id,summary,text) values (112,'2014-07-12 10:00:00',1,'Is this secure?','This message is for Luke');
|
||||
Reference in New Issue
Block a user