SEC-524: Added "var" attribute to authorize and accesscontrollist JSP tags.

Allows the result of the boolean condition granting/denying access to be stored in the page context for later use, without having to duplicate the tag.
This commit is contained in:
Luke Taylor
2010-03-24 18:35:17 +00:00
parent 2e2625873c
commit bf91f2ca67
11 changed files with 153 additions and 32 deletions

View File

@@ -66,6 +66,7 @@ import org.springframework.web.util.ExpressionEvaluationUtils;
* implementations are found in the application context.
*
* @author Ben Alex
* @author Luke Taylor
*/
public class AccessControlListTag extends TagSupport {
//~ Static fields/initializers =====================================================================================
@@ -81,12 +82,13 @@ public class AccessControlListTag extends TagSupport {
private SidRetrievalStrategy sidRetrievalStrategy;
private PermissionFactory permissionFactory;
private String hasPermission = "";
private String var;
//~ Methods ========================================================================================================
public int doStartTag() throws JspException {
if ((null == hasPermission) || "".equals(hasPermission)) {
return Tag.SKIP_BODY;
return skipBody();
}
initializeIfRequired();
@@ -111,7 +113,7 @@ public class AccessControlListTag extends TagSupport {
}
// Of course they have access to a null object!
return Tag.EVAL_BODY_INCLUDE;
return evalBody();
}
if (SecurityContextHolder.getContext().getAuthentication() == null) {
@@ -120,7 +122,7 @@ public class AccessControlListTag extends TagSupport {
"SecurityContextHolder did not return a non-null Authentication object, so skipping tag body");
}
return Tag.SKIP_BODY;
return skipBody();
}
List<Sid> sids = sidRetrievalStrategy.getSids(SecurityContextHolder.getContext().getAuthentication());
@@ -131,15 +133,30 @@ public class AccessControlListTag extends TagSupport {
Acl acl = aclService.readAclById(oid, sids);
if (acl.isGranted(requiredPermissions, sids, false)) {
return Tag.EVAL_BODY_INCLUDE;
return evalBody();
} else {
return Tag.SKIP_BODY;
return skipBody();
}
} catch (NotFoundException nfe) {
return Tag.SKIP_BODY;
return skipBody();
}
}
private int skipBody() {
if (var != null) {
pageContext.setAttribute(var, Boolean.FALSE, PageContext.PAGE_SCOPE);
}
return SKIP_BODY;
}
private int evalBody() {
if (var != null) {
pageContext.setAttribute(var, Boolean.TRUE, PageContext.PAGE_SCOPE);
}
return EVAL_BODY_INCLUDE;
}
/**
* Allows test cases to override where application context obtained from.
*
@@ -233,4 +250,8 @@ public class AccessControlListTag extends TagSupport {
public void setHasPermission(String hasPermission) {
this.hasPermission = hasPermission;
}
public void setVar(String var) {
this.var = var;
}
}

View File

@@ -10,6 +10,7 @@ import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.jsp.JspException;
import javax.servlet.jsp.PageContext;
import org.springframework.context.ApplicationContext;
import org.springframework.expression.Expression;
@@ -35,6 +36,7 @@ public class AuthorizeTag extends LegacyAuthorizeTag {
private String access;
private String url;
private String method;
private String var;
// If access expression evaluates to "true" return
public int doStartTag() throws JspException {
@@ -44,13 +46,21 @@ public class AuthorizeTag extends LegacyAuthorizeTag {
return SKIP_BODY;
}
int result;
if (access != null && access.length() > 0) {
return authorizeUsingAccessExpression(currentUser);
result = authorizeUsingAccessExpression(currentUser);
} else if (url != null && url.length() > 0) {
return authorizeUsingUrlCheck(currentUser);
result = authorizeUsingUrlCheck(currentUser);
} else {
result = super.doStartTag();
}
return super.doStartTag();
if (var != null) {
pageContext.setAttribute(var, Boolean.valueOf(result == EVAL_BODY_INCLUDE), PageContext.PAGE_SCOPE);
}
return result;
}
private int authorizeUsingAccessExpression(Authentication currentUser) throws JspException {
@@ -91,6 +101,10 @@ public class AuthorizeTag extends LegacyAuthorizeTag {
this.method = method;
}
public void setVar(String var) {
this.var = var;
}
WebSecurityExpressionHandler getExpressionHandler() throws JspException {
ServletContext servletContext = pageContext.getServletContext();
ApplicationContext ctx = WebApplicationContextUtils.getRequiredWebApplicationContext(servletContext);

View File

@@ -9,7 +9,6 @@
<uri>http://www.springframework.org/security/tags</uri>
<description>
Spring Security Authorization Tag Library
$Id$
</description>
<tag>
@@ -51,6 +50,15 @@
</description>
</attribute>
<attribute>
<name>var</name>
<required>false</required>
<rtexprvalue>false</rtexprvalue>
<description>
A page scoped variable into which the boolean result of the tag evaluation will be written, allowing the
same condition to be reused subsequently in the page without re-evaluation.
</description>
</attribute>
<attribute>
<name>ifNotGranted</name>
@@ -153,6 +161,15 @@
are being evaluated.
</description>
</attribute>
<attribute>
<name>var</name>
<required>false</required>
<rtexprvalue>false</rtexprvalue>
<description>
A page scoped variable into which the boolean result of the tag evaluation will be written, allowing the
same condition to be reused subsequently in the page without re-evaluation.
</description>
</attribute>
</tag>
</taglib>