Replace deprecated #check calls with #authorize
Closes gh-16936 Signed-off-by: Evgeniy Cheban <mister.cheban@gmail.com>
This commit is contained in:
committed by
Josh Cummings
parent
e3add59550
commit
b0cecb37d2
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright 2002-2024 the original author or authors.
|
* Copyright 2002-2025 the original author or authors.
|
||||||
*
|
*
|
||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
* you may not use this file except in compliance with the License.
|
* you may not use this file except in compliance with the License.
|
||||||
@@ -85,6 +85,7 @@ import org.springframework.web.servlet.handler.HandlerMappingIntrospector;
|
|||||||
|
|
||||||
import static org.assertj.core.api.Assertions.assertThat;
|
import static org.assertj.core.api.Assertions.assertThat;
|
||||||
import static org.assertj.core.api.Assertions.assertThatExceptionOfType;
|
import static org.assertj.core.api.Assertions.assertThatExceptionOfType;
|
||||||
|
import static org.mockito.BDDMockito.given;
|
||||||
import static org.mockito.Mockito.any;
|
import static org.mockito.Mockito.any;
|
||||||
import static org.mockito.Mockito.atLeastOnce;
|
import static org.mockito.Mockito.atLeastOnce;
|
||||||
import static org.mockito.Mockito.doCallRealMethod;
|
import static org.mockito.Mockito.doCallRealMethod;
|
||||||
@@ -153,6 +154,7 @@ public class AuthorizeHttpRequestsConfigurerTests {
|
|||||||
@Test
|
@Test
|
||||||
public void configureMvcMatcherAccessAuthorizationManagerWhenNotNullThenVerifyUse() throws Exception {
|
public void configureMvcMatcherAccessAuthorizationManagerWhenNotNullThenVerifyUse() throws Exception {
|
||||||
CustomAuthorizationManagerConfig.authorizationManager = mock(AuthorizationManager.class);
|
CustomAuthorizationManagerConfig.authorizationManager = mock(AuthorizationManager.class);
|
||||||
|
given(CustomAuthorizationManagerConfig.authorizationManager.authorize(any(), any())).willCallRealMethod();
|
||||||
this.spring.register(CustomAuthorizationManagerConfig.class, BasicController.class).autowire();
|
this.spring.register(CustomAuthorizationManagerConfig.class, BasicController.class).autowire();
|
||||||
this.mvc.perform(get("/")).andExpect(status().isOk());
|
this.mvc.perform(get("/")).andExpect(status().isOk());
|
||||||
verify(CustomAuthorizationManagerConfig.authorizationManager).check(any(), any());
|
verify(CustomAuthorizationManagerConfig.authorizationManager).check(any(), any());
|
||||||
@@ -161,6 +163,8 @@ public class AuthorizeHttpRequestsConfigurerTests {
|
|||||||
@Test
|
@Test
|
||||||
public void configureNoParameterMvcMatcherAccessAuthorizationManagerWhenNotNullThenVerifyUse() throws Exception {
|
public void configureNoParameterMvcMatcherAccessAuthorizationManagerWhenNotNullThenVerifyUse() throws Exception {
|
||||||
CustomAuthorizationManagerNoParameterConfig.authorizationManager = mock(AuthorizationManager.class);
|
CustomAuthorizationManagerNoParameterConfig.authorizationManager = mock(AuthorizationManager.class);
|
||||||
|
given(CustomAuthorizationManagerNoParameterConfig.authorizationManager.authorize(any(), any()))
|
||||||
|
.willCallRealMethod();
|
||||||
this.spring.register(CustomAuthorizationManagerNoParameterConfig.class, BasicController.class).autowire();
|
this.spring.register(CustomAuthorizationManagerNoParameterConfig.class, BasicController.class).autowire();
|
||||||
this.mvc.perform(get("/")).andExpect(status().isOk());
|
this.mvc.perform(get("/")).andExpect(status().isOk());
|
||||||
verify(CustomAuthorizationManagerNoParameterConfig.authorizationManager).check(any(), any());
|
verify(CustomAuthorizationManagerNoParameterConfig.authorizationManager).check(any(), any());
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright 2002-2024 the original author or authors.
|
* Copyright 2002-2025 the original author or authors.
|
||||||
*
|
*
|
||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
* you may not use this file except in compliance with the License.
|
* you may not use this file except in compliance with the License.
|
||||||
@@ -39,9 +39,9 @@ public interface AuthorizationManager<T> {
|
|||||||
* @throws AccessDeniedException if access is not granted
|
* @throws AccessDeniedException if access is not granted
|
||||||
*/
|
*/
|
||||||
default void verify(Supplier<Authentication> authentication, T object) {
|
default void verify(Supplier<Authentication> authentication, T object) {
|
||||||
AuthorizationDecision decision = check(authentication, object);
|
AuthorizationResult result = authorize(authentication, object);
|
||||||
if (decision != null && !decision.isGranted()) {
|
if (result != null && !result.isGranted()) {
|
||||||
throw new AuthorizationDeniedException("Access Denied", decision);
|
throw new AuthorizationDeniedException("Access Denied", result);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright 2002-2024 the original author or authors.
|
* Copyright 2002-2025 the original author or authors.
|
||||||
*
|
*
|
||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
* you may not use this file except in compliance with the License.
|
* you may not use this file except in compliance with the License.
|
||||||
@@ -67,6 +67,19 @@ public final class ObservationAuthorizationManager<T>
|
|||||||
@Deprecated
|
@Deprecated
|
||||||
@Override
|
@Override
|
||||||
public AuthorizationDecision check(Supplier<Authentication> authentication, T object) {
|
public AuthorizationDecision check(Supplier<Authentication> authentication, T object) {
|
||||||
|
AuthorizationResult result = authorize(authentication, object);
|
||||||
|
if (result == null) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
if (result instanceof AuthorizationDecision decision) {
|
||||||
|
return decision;
|
||||||
|
}
|
||||||
|
throw new IllegalArgumentException(
|
||||||
|
"Please call #authorize or ensure that the returned result is of type AuthorizationDecision");
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public AuthorizationResult authorize(Supplier<Authentication> authentication, T object) {
|
||||||
AuthorizationObservationContext<T> context = new AuthorizationObservationContext<>(object);
|
AuthorizationObservationContext<T> context = new AuthorizationObservationContext<>(object);
|
||||||
Supplier<Authentication> wrapped = () -> {
|
Supplier<Authentication> wrapped = () -> {
|
||||||
context.setAuthentication(authentication.get());
|
context.setAuthentication(authentication.get());
|
||||||
@@ -74,13 +87,13 @@ public final class ObservationAuthorizationManager<T>
|
|||||||
};
|
};
|
||||||
Observation observation = Observation.createNotStarted(this.convention, () -> context, this.registry).start();
|
Observation observation = Observation.createNotStarted(this.convention, () -> context, this.registry).start();
|
||||||
try (Observation.Scope scope = observation.openScope()) {
|
try (Observation.Scope scope = observation.openScope()) {
|
||||||
AuthorizationDecision decision = this.delegate.check(wrapped, object);
|
AuthorizationResult result = this.delegate.authorize(wrapped, object);
|
||||||
context.setAuthorizationResult(decision);
|
context.setAuthorizationResult(result);
|
||||||
if (decision != null && !decision.isGranted()) {
|
if (result != null && !result.isGranted()) {
|
||||||
observation.error(new AccessDeniedException(
|
observation.error(new AccessDeniedException(
|
||||||
this.messages.getMessage("AbstractAccessDecisionManager.accessDenied", "Access Denied")));
|
this.messages.getMessage("AbstractAccessDecisionManager.accessDenied", "Access Denied")));
|
||||||
}
|
}
|
||||||
return decision;
|
return result;
|
||||||
}
|
}
|
||||||
catch (Throwable ex) {
|
catch (Throwable ex) {
|
||||||
observation.error(ex);
|
observation.error(ex);
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright 2002-2023 the original author or authors.
|
* Copyright 2002-2025 the original author or authors.
|
||||||
*
|
*
|
||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
* you may not use this file except in compliance with the License.
|
* you may not use this file except in compliance with the License.
|
||||||
@@ -74,6 +74,7 @@ public class ObservationAuthorizationManagerTests {
|
|||||||
void verifyWhenDefaultsThenObserves() {
|
void verifyWhenDefaultsThenObserves() {
|
||||||
given(this.handler.supportsContext(any())).willReturn(true);
|
given(this.handler.supportsContext(any())).willReturn(true);
|
||||||
given(this.authorizationManager.check(any(), any())).willReturn(this.grant);
|
given(this.authorizationManager.check(any(), any())).willReturn(this.grant);
|
||||||
|
given(this.authorizationManager.authorize(any(), any())).willCallRealMethod();
|
||||||
this.tested.verify(this.token, this.object);
|
this.tested.verify(this.token, this.object);
|
||||||
ArgumentCaptor<Observation.Context> captor = ArgumentCaptor.forClass(Observation.Context.class);
|
ArgumentCaptor<Observation.Context> captor = ArgumentCaptor.forClass(Observation.Context.class);
|
||||||
verify(this.handler).onStart(captor.capture());
|
verify(this.handler).onStart(captor.capture());
|
||||||
@@ -92,6 +93,7 @@ public class ObservationAuthorizationManagerTests {
|
|||||||
this.tested.setMessageSource(source);
|
this.tested.setMessageSource(source);
|
||||||
given(this.handler.supportsContext(any())).willReturn(true);
|
given(this.handler.supportsContext(any())).willReturn(true);
|
||||||
given(this.authorizationManager.check(any(), any())).willReturn(this.deny);
|
given(this.authorizationManager.check(any(), any())).willReturn(this.deny);
|
||||||
|
given(this.authorizationManager.authorize(any(), any())).willCallRealMethod();
|
||||||
given(source.getMessage(eq("AbstractAccessDecisionManager.accessDenied"), any(), any(), any()))
|
given(source.getMessage(eq("AbstractAccessDecisionManager.accessDenied"), any(), any(), any()))
|
||||||
.willReturn("accessDenied");
|
.willReturn("accessDenied");
|
||||||
assertThatExceptionOfType(AccessDeniedException.class)
|
assertThatExceptionOfType(AccessDeniedException.class)
|
||||||
@@ -116,6 +118,7 @@ public class ObservationAuthorizationManagerTests {
|
|||||||
((Supplier<Authentication>) invocation.getArgument(0)).get();
|
((Supplier<Authentication>) invocation.getArgument(0)).get();
|
||||||
return this.grant;
|
return this.grant;
|
||||||
});
|
});
|
||||||
|
given(this.authorizationManager.authorize(any(), any())).willCallRealMethod();
|
||||||
this.tested.verify(this.token, this.object);
|
this.tested.verify(this.token, this.object);
|
||||||
ArgumentCaptor<Observation.Context> captor = ArgumentCaptor.forClass(Observation.Context.class);
|
ArgumentCaptor<Observation.Context> captor = ArgumentCaptor.forClass(Observation.Context.class);
|
||||||
verify(this.handler).onStart(captor.capture());
|
verify(this.handler).onStart(captor.capture());
|
||||||
|
|||||||
@@ -30,6 +30,7 @@ import org.springframework.security.authorization.AuthenticatedAuthorizationMana
|
|||||||
import org.springframework.security.authorization.AuthorityAuthorizationManager;
|
import org.springframework.security.authorization.AuthorityAuthorizationManager;
|
||||||
import org.springframework.security.authorization.AuthorizationDecision;
|
import org.springframework.security.authorization.AuthorizationDecision;
|
||||||
import org.springframework.security.authorization.AuthorizationManager;
|
import org.springframework.security.authorization.AuthorizationManager;
|
||||||
|
import org.springframework.security.authorization.AuthorizationResult;
|
||||||
import org.springframework.security.authorization.SingleResultAuthorizationManager;
|
import org.springframework.security.authorization.SingleResultAuthorizationManager;
|
||||||
import org.springframework.security.core.Authentication;
|
import org.springframework.security.core.Authentication;
|
||||||
import org.springframework.security.messaging.util.matcher.MessageMatcher;
|
import org.springframework.security.messaging.util.matcher.MessageMatcher;
|
||||||
@@ -63,11 +64,24 @@ public final class MessageMatcherDelegatingAuthorizationManager implements Autho
|
|||||||
* @return an {@link AuthorizationDecision}. If there is no {@link MessageMatcher}
|
* @return an {@link AuthorizationDecision}. If there is no {@link MessageMatcher}
|
||||||
* matching the message, or the {@link AuthorizationManager} could not decide, then
|
* matching the message, or the {@link AuthorizationManager} could not decide, then
|
||||||
* null is returned
|
* null is returned
|
||||||
* @deprecated please use {@link #authorize(Supplier, Object)} instead
|
* @deprecated please use {@link #authorize(Supplier, Message)} instead
|
||||||
*/
|
*/
|
||||||
@Deprecated
|
@Deprecated
|
||||||
@Override
|
@Override
|
||||||
public AuthorizationDecision check(Supplier<Authentication> authentication, Message<?> message) {
|
public AuthorizationDecision check(Supplier<Authentication> authentication, Message<?> message) {
|
||||||
|
AuthorizationResult result = authorize(authentication, message);
|
||||||
|
if (result == null) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
if (result instanceof AuthorizationDecision decision) {
|
||||||
|
return decision;
|
||||||
|
}
|
||||||
|
throw new IllegalArgumentException(
|
||||||
|
"Please call #authorize or ensure that the returned result is of type AuthorizationDecision");
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public AuthorizationResult authorize(Supplier<Authentication> authentication, Message<?> message) {
|
||||||
if (this.logger.isTraceEnabled()) {
|
if (this.logger.isTraceEnabled()) {
|
||||||
this.logger.trace(LogMessage.format("Authorizing message"));
|
this.logger.trace(LogMessage.format("Authorizing message"));
|
||||||
}
|
}
|
||||||
@@ -79,7 +93,7 @@ public final class MessageMatcherDelegatingAuthorizationManager implements Autho
|
|||||||
if (this.logger.isTraceEnabled()) {
|
if (this.logger.isTraceEnabled()) {
|
||||||
this.logger.trace(LogMessage.format("Checking authorization on message using %s", manager));
|
this.logger.trace(LogMessage.format("Checking authorization on message using %s", manager));
|
||||||
}
|
}
|
||||||
return manager.check(authentication, authorizationContext);
|
return manager.authorize(authentication, authorizationContext);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
this.logger.trace("Abstaining since did not find matching MessageMatcher");
|
this.logger.trace("Abstaining since did not find matching MessageMatcher");
|
||||||
|
|||||||
@@ -30,6 +30,7 @@ import org.springframework.security.authorization.AuthenticatedAuthorizationMana
|
|||||||
import org.springframework.security.authorization.AuthorityAuthorizationManager;
|
import org.springframework.security.authorization.AuthorityAuthorizationManager;
|
||||||
import org.springframework.security.authorization.AuthorizationDecision;
|
import org.springframework.security.authorization.AuthorizationDecision;
|
||||||
import org.springframework.security.authorization.AuthorizationManager;
|
import org.springframework.security.authorization.AuthorizationManager;
|
||||||
|
import org.springframework.security.authorization.AuthorizationResult;
|
||||||
import org.springframework.security.authorization.SingleResultAuthorizationManager;
|
import org.springframework.security.authorization.SingleResultAuthorizationManager;
|
||||||
import org.springframework.security.core.Authentication;
|
import org.springframework.security.core.Authentication;
|
||||||
import org.springframework.security.web.util.UrlUtils;
|
import org.springframework.security.web.util.UrlUtils;
|
||||||
@@ -69,11 +70,24 @@ public final class RequestMatcherDelegatingAuthorizationManager implements Autho
|
|||||||
* @return an {@link AuthorizationDecision}. If there is no {@link RequestMatcher}
|
* @return an {@link AuthorizationDecision}. If there is no {@link RequestMatcher}
|
||||||
* matching the request, or the {@link AuthorizationManager} could not decide, then
|
* matching the request, or the {@link AuthorizationManager} could not decide, then
|
||||||
* null is returned
|
* null is returned
|
||||||
* @deprecated please use {@link #authorize(Supplier, Object)} instead
|
* @deprecated please use {@link #authorize(Supplier, HttpServletRequest)} instead
|
||||||
*/
|
*/
|
||||||
@Deprecated
|
@Deprecated
|
||||||
@Override
|
@Override
|
||||||
public AuthorizationDecision check(Supplier<Authentication> authentication, HttpServletRequest request) {
|
public AuthorizationDecision check(Supplier<Authentication> authentication, HttpServletRequest request) {
|
||||||
|
AuthorizationResult result = authorize(authentication, request);
|
||||||
|
if (result == null) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
if (result instanceof AuthorizationDecision decision) {
|
||||||
|
return decision;
|
||||||
|
}
|
||||||
|
throw new IllegalArgumentException(
|
||||||
|
"Please call #authorize or ensure that the returned result is of type AuthorizationDecision");
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public AuthorizationResult authorize(Supplier<Authentication> authentication, HttpServletRequest request) {
|
||||||
if (this.logger.isTraceEnabled()) {
|
if (this.logger.isTraceEnabled()) {
|
||||||
this.logger.trace(LogMessage.format("Authorizing %s", requestLine(request)));
|
this.logger.trace(LogMessage.format("Authorizing %s", requestLine(request)));
|
||||||
}
|
}
|
||||||
@@ -87,7 +101,7 @@ public final class RequestMatcherDelegatingAuthorizationManager implements Autho
|
|||||||
this.logger.trace(
|
this.logger.trace(
|
||||||
LogMessage.format("Checking authorization on %s using %s", requestLine(request), manager));
|
LogMessage.format("Checking authorization on %s using %s", requestLine(request), manager));
|
||||||
}
|
}
|
||||||
return manager.check(authentication,
|
return manager.authorize(authentication,
|
||||||
new RequestAuthorizationContext(request, matchResult.getVariables()));
|
new RequestAuthorizationContext(request, matchResult.getVariables()));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user