Class AuthenticationTrustResolverImpl
java.lang.Object
org.springframework.security.authentication.AuthenticationTrustResolverImpl
- All Implemented Interfaces:
AuthenticationTrustResolver
Basic implementation of
AuthenticationTrustResolver.
Makes trust decisions based on whether the passed Authentication is an
instance of a defined class.
If anonymousClass or rememberMeClass is null, the
corresponding method will always return false.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionbooleanisAnonymous(@Nullable Authentication authentication) Indicates whether the passedAuthenticationtoken represents an anonymous user.booleanisRememberMe(@Nullable Authentication authentication) Indicates whether the passedAuthenticationtoken represents user that has been remembered (i.e.voidsetAnonymousClass(Class<? extends Authentication> anonymousClass) voidsetRememberMeClass(Class<? extends Authentication> rememberMeClass) Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface org.springframework.security.authentication.AuthenticationTrustResolver
isAuthenticated, isFullyAuthenticated
-
Constructor Details
-
AuthenticationTrustResolverImpl
public AuthenticationTrustResolverImpl()
-
-
Method Details
-
isAnonymous
Description copied from interface:AuthenticationTrustResolverIndicates whether the passedAuthenticationtoken represents an anonymous user. Typically the framework will call this method if it is trying to decide whether anAccessDeniedExceptionshould result in a final rejection (i.e. as would be the case if the principal was non-anonymous/fully authenticated) or direct the principal to attempt actual authentication (i.e. as would be the case if theAuthenticationwas merely anonymous).- Specified by:
isAnonymousin interfaceAuthenticationTrustResolver- Parameters:
authentication- to test (may benullin which case the method will always returnfalse)- Returns:
truethe passed authentication token represented an anonymous principal,falseotherwise
-
isRememberMe
Description copied from interface:AuthenticationTrustResolverIndicates whether the passedAuthenticationtoken represents user that has been remembered (i.e. not a user that has been fully authenticated).The method is provided to assist with custom
AccessDecisionVoters and the like that you might develop. Of course, you don't need to use this method either and can develop your own "trust level" hierarchy instead.- Specified by:
isRememberMein interfaceAuthenticationTrustResolver- Parameters:
authentication- to test (may benullin which case the method will always returnfalse)- Returns:
truethe passed authentication token represented a principal authenticated using a remember-me token,falseotherwise
-
setAnonymousClass
-
setRememberMeClass
-