Class RequestMatcherDelegatingWebInvocationPrivilegeEvaluator
java.lang.Object
org.springframework.security.web.access.RequestMatcherDelegatingWebInvocationPrivilegeEvaluator
- All Implemented Interfaces:
org.springframework.beans.factory.Aware,WebInvocationPrivilegeEvaluator,org.springframework.web.context.ServletContextAware
@Deprecated
public final class RequestMatcherDelegatingWebInvocationPrivilegeEvaluator
extends Object
implements WebInvocationPrivilegeEvaluator, org.springframework.web.context.ServletContextAware
Deprecated.
A
WebInvocationPrivilegeEvaluator which delegates to a list of
WebInvocationPrivilegeEvaluator based on a
RequestMatcher evaluation- Since:
- 5.5.5
-
Constructor Summary
ConstructorsConstructorDescriptionRequestMatcherDelegatingWebInvocationPrivilegeEvaluator(List<RequestMatcherEntry<List<WebInvocationPrivilegeEvaluator>>> requestMatcherPrivilegeEvaluatorsEntries) Deprecated. -
Method Summary
Modifier and TypeMethodDescriptionbooleanisAllowed(String uri, @Nullable Authentication authentication) Deprecated.Determines whether the user represented by the supplied Authentication object is allowed to invoke the supplied URI.booleanisAllowed(String contextPath, String uri, @Nullable String method, @Nullable Authentication authentication) Deprecated.Determines whether the user represented by the supplied Authentication object is allowed to invoke the supplied URI.voidsetServletContext(jakarta.servlet.ServletContext servletContext) Deprecated.
-
Constructor Details
-
RequestMatcherDelegatingWebInvocationPrivilegeEvaluator
public RequestMatcherDelegatingWebInvocationPrivilegeEvaluator(List<RequestMatcherEntry<List<WebInvocationPrivilegeEvaluator>>> requestMatcherPrivilegeEvaluatorsEntries) Deprecated.
-
-
Method Details
-
isAllowed
Deprecated.Determines whether the user represented by the supplied Authentication object is allowed to invoke the supplied URI.Uses the provided URI in the
RequestMatcher.matches(HttpServletRequest)for everyRequestMatcherconfigured. If noRequestMatcheris matched, or if there is not an availableWebInvocationPrivilegeEvaluator, returnstrue.- Specified by:
isAllowedin interfaceWebInvocationPrivilegeEvaluator- Parameters:
uri- the URI excluding the context path (a default context path setting will be used)- Returns:
- true if access is allowed, false if denied
-
isAllowed
public boolean isAllowed(String contextPath, String uri, @Nullable String method, @Nullable Authentication authentication) Deprecated.Determines whether the user represented by the supplied Authentication object is allowed to invoke the supplied URI.Uses the provided URI in the
RequestMatcher.matches(HttpServletRequest)for everyRequestMatcherconfigured. If noRequestMatcheris matched, or if there is not an availableWebInvocationPrivilegeEvaluator, returnstrue.- Specified by:
isAllowedin interfaceWebInvocationPrivilegeEvaluator- Parameters:
uri- the URI excluding the context path (a default context path setting will be used)contextPath- the context path (may be null, in which case a default value will be used).method- the HTTP method (or null, for any method)authentication- the Authentication instance whose authorities should be used in evaluation whether access should be granted.- Returns:
- true if access is allowed, false if denied
-
setServletContext
public void setServletContext(jakarta.servlet.ServletContext servletContext) Deprecated.- Specified by:
setServletContextin interfaceorg.springframework.web.context.ServletContextAware
-
AuthorizationManagerWebInvocationPrivilegeEvaluatorand adapt any delegateWebInvocationPrivilegeEvaluators intoAuthorizationManagers