Class DefaultWebInvocationPrivilegeEvaluator
java.lang.Object
org.springframework.security.web.access.DefaultWebInvocationPrivilegeEvaluator
- All Implemented Interfaces:
- org.springframework.beans.factory.Aware,- WebInvocationPrivilegeEvaluator,- org.springframework.web.context.ServletContextAware
@Deprecated
public class DefaultWebInvocationPrivilegeEvaluator
extends Object
implements WebInvocationPrivilegeEvaluator, org.springframework.web.context.ServletContextAware
Deprecated.
Allows users to determine whether they have privileges for a given web URI.
- Since:
- 3.0
- 
Field SummaryFieldsModifier and TypeFieldDescriptionprotected static final org.apache.commons.logging.LogDeprecated.
- 
Constructor SummaryConstructorsConstructorDescriptionDefaultWebInvocationPrivilegeEvaluator(AbstractSecurityInterceptor securityInterceptor) Deprecated.
- 
Method SummaryModifier and TypeMethodDescriptionbooleanisAllowed(String contextPath, String uri, String method, Authentication authentication) Deprecated.Determines whether the user represented by the supplied Authentication object is allowed to invoke the supplied URI, with the given .booleanisAllowed(String uri, Authentication authentication) Deprecated.Determines whether the user represented by the supplied Authentication object is allowed to invoke the supplied URI.voidsetServletContext(jakarta.servlet.ServletContext servletContext) Deprecated.
- 
Field Details- 
loggerprotected static final org.apache.commons.logging.Log loggerDeprecated.
 
- 
- 
Constructor Details- 
DefaultWebInvocationPrivilegeEvaluatorDeprecated.
 
- 
- 
Method Details- 
isAllowedDeprecated.Determines whether the user represented by the supplied Authentication object is allowed to invoke the supplied URI.- Specified by:
- isAllowedin interface- WebInvocationPrivilegeEvaluator
- Parameters:
- uri- the URI excluding the context path (a default context path setting will be used)
 
- 
isAllowedpublic boolean isAllowed(String contextPath, String uri, String method, Authentication authentication) Deprecated.Determines whether the user represented by the supplied Authentication object is allowed to invoke the supplied URI, with the given .Note the default implementation of FilterInvocationSecurityMetadataSource disregards the contextPathwhen evaluating which secure object metadata applies to a given request URI, so generally thecontextPathis unimportant unless you are using a customFilterInvocationSecurityMetadataSource.- Specified by:
- isAllowedin interface- WebInvocationPrivilegeEvaluator
- Parameters:
- uri- the URI excluding the context path
- contextPath- the context path (may be null, in which case a default value will be used).
- method- the HTTP method (or null, for any method)
- authentication- the Authentication instance whose authorities should be used in evaluation whether access should be granted.
- Returns:
- true if access is allowed, false if denied
 
- 
setServletContextpublic void setServletContext(jakarta.servlet.ServletContext servletContext) Deprecated.- Specified by:
- setServletContextin interface- org.springframework.web.context.ServletContextAware
 
 
- 
AuthorizationManagerWebInvocationPrivilegeEvaluatorinstead