Interface AccessDecisionVoter<S>
- All Known Implementing Classes:
- AbstractAclVoter,- AclEntryVoter,- AuthenticatedVoter,- Jsr250Voter,- MessageExpressionVoter,- PreInvocationAuthorizationAdviceVoter,- RoleHierarchyVoter,- RoleVoter,- WebExpressionVoter
 The coordination of voting (ie polling AccessDecisionVoters, tallying their
 responses, and making the final authorization decision) is performed by an
 AccessDecisionManager.
- 
Field SummaryFieldsModifier and TypeFieldDescriptionstatic final intDeprecated.static final intDeprecated.static final intDeprecated.
- 
Method SummaryModifier and TypeMethodDescriptionbooleanDeprecated.Indicates whether theAccessDecisionVoterimplementation is able to provide access control votes for the indicated secured object type.booleansupports(ConfigAttribute attribute) Deprecated.Indicates whether thisAccessDecisionVoteris able to vote on the passedConfigAttribute.intvote(Authentication authentication, S object, Collection<ConfigAttribute> attributes) Deprecated.Indicates whether or not access is granted.
- 
Field Details- 
ACCESS_GRANTEDstatic final int ACCESS_GRANTEDDeprecated.- See Also:
 
- 
ACCESS_ABSTAINstatic final int ACCESS_ABSTAINDeprecated.- See Also:
 
- 
ACCESS_DENIEDstatic final int ACCESS_DENIEDDeprecated.- See Also:
 
 
- 
- 
Method Details- 
supportsDeprecated.Indicates whether thisAccessDecisionVoteris able to vote on the passedConfigAttribute.This allows the AbstractSecurityInterceptorto check every configuration attribute can be consumed by the configuredAccessDecisionManagerand/orRunAsManagerand/orAfterInvocationManager.- Parameters:
- attribute- a configuration attribute that has been configured against the- AbstractSecurityInterceptor
- Returns:
- true if this AccessDecisionVotercan support the passed configuration attribute
 
- 
supportsDeprecated.Indicates whether theAccessDecisionVoterimplementation is able to provide access control votes for the indicated secured object type.- Parameters:
- clazz- the class that is being queried
- Returns:
- true if the implementation can process the indicated class
 
- 
voteDeprecated.Indicates whether or not access is granted.The decision must be affirmative ( ACCESS_GRANTED), negative (ACCESS_DENIED) or theAccessDecisionVotercan abstain (ACCESS_ABSTAIN) from voting. Under no circumstances should implementing classes return any other value. If a weighting of results is desired, this should be handled in a customAccessDecisionManagerinstead.Unless an AccessDecisionVoteris specifically intended to vote on an access control decision due to a passed method invocation or configuration attribute parameter, it must returnACCESS_ABSTAIN. This prevents the coordinatingAccessDecisionManagerfrom counting votes from thoseAccessDecisionVoters without a legitimate interest in the access control decision.Whilst the secured object (such as a MethodInvocation) is passed as a parameter to maximise flexibility in making access control decisions, implementing classes should not modify it or cause the represented invocation to take place (for example, by callingMethodInvocation.proceed()).- Parameters:
- authentication- the caller making the invocation
- object- the secured object being invoked
- attributes- the configuration attributes associated with the secured object
- Returns:
- either ACCESS_GRANTED,ACCESS_ABSTAINorACCESS_DENIED
 
 
- 
AuthorizationManagerinstead