| Classes in this File | Line Coverage | Branch Coverage | Complexity | ||||||||
| MethodSecurityInterceptor |
|
| 1.0;1 |
| 1 | /* Copyright 2004, 2005, 2006 Acegi Technology Pty Limited |
|
| 2 | * |
|
| 3 | * Licensed under the Apache License, Version 2.0 (the "License"); |
|
| 4 | * you may not use this file except in compliance with the License. |
|
| 5 | * You may obtain a copy of the License at |
|
| 6 | * |
|
| 7 | * http://www.apache.org/licenses/LICENSE-2.0 |
|
| 8 | * |
|
| 9 | * Unless required by applicable law or agreed to in writing, software |
|
| 10 | * distributed under the License is distributed on an "AS IS" BASIS, |
|
| 11 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|
| 12 | * See the License for the specific language governing permissions and |
|
| 13 | * limitations under the License. |
|
| 14 | */ |
|
| 15 | ||
| 16 | package org.acegisecurity.intercept.method.aopalliance; |
|
| 17 | ||
| 18 | import org.acegisecurity.intercept.AbstractSecurityInterceptor; |
|
| 19 | import org.acegisecurity.intercept.InterceptorStatusToken; |
|
| 20 | import org.acegisecurity.intercept.ObjectDefinitionSource; |
|
| 21 | import org.acegisecurity.intercept.method.MethodDefinitionSource; |
|
| 22 | ||
| 23 | import org.aopalliance.intercept.MethodInterceptor; |
|
| 24 | import org.aopalliance.intercept.MethodInvocation; |
|
| 25 | ||
| 26 | ||
| 27 | /** |
|
| 28 | * Provides security interception of AOP Alliance based method invocations.<p>The |
|
| 29 | * <code>ObjectDefinitionSource</code> required by this security interceptor is of type {@link |
|
| 30 | * MethodDefinitionSource}. This is shared with the AspectJ based security interceptor |
|
| 31 | * (<code>AspectJSecurityInterceptor</code>), since both work with Java <code>Method</code>s.</p> |
|
| 32 | * <P>Refer to {@link AbstractSecurityInterceptor} for details on the workflow.</p> |
|
| 33 | * |
|
| 34 | * @author Ben Alex |
|
| 35 | * @version $Id: MethodSecurityInterceptor.java 1496 2006-05-23 13:38:33Z benalex $ |
|
| 36 | */ |
|
| 37 | 34 | public class MethodSecurityInterceptor extends AbstractSecurityInterceptor implements MethodInterceptor { |
| 38 | //~ Instance fields ================================================================================================ |
|
| 39 | ||
| 40 | private MethodDefinitionSource objectDefinitionSource; |
|
| 41 | ||
| 42 | //~ Methods ======================================================================================================== |
|
| 43 | ||
| 44 | public MethodDefinitionSource getObjectDefinitionSource() { |
|
| 45 | 10 | return this.objectDefinitionSource; |
| 46 | } |
|
| 47 | ||
| 48 | public Class getSecureObjectClass() { |
|
| 49 | 225 | return MethodInvocation.class; |
| 50 | } |
|
| 51 | ||
| 52 | /** |
|
| 53 | * This method should be used to enforce security on a <code>MethodInvocation</code>. |
|
| 54 | * |
|
| 55 | * @param mi The method being invoked which requires a security decision |
|
| 56 | * |
|
| 57 | * @return The returned value from the method invocation |
|
| 58 | * |
|
| 59 | * @throws Throwable if any error occurs |
|
| 60 | */ |
|
| 61 | public Object invoke(MethodInvocation mi) throws Throwable { |
|
| 62 | 34 | Object result = null; |
| 63 | 34 | InterceptorStatusToken token = super.beforeInvocation(mi); |
| 64 | ||
| 65 | try { |
|
| 66 | 24 | result = mi.proceed(); |
| 67 | } finally { |
|
| 68 | 24 | result = super.afterInvocation(token, result); |
| 69 | 24 | } |
| 70 | ||
| 71 | 24 | return result; |
| 72 | } |
|
| 73 | ||
| 74 | public ObjectDefinitionSource obtainObjectDefinitionSource() { |
|
| 75 | 101 | return this.objectDefinitionSource; |
| 76 | } |
|
| 77 | ||
| 78 | public void setObjectDefinitionSource(MethodDefinitionSource newSource) { |
|
| 79 | 31 | this.objectDefinitionSource = newSource; |
| 80 | 31 | } |
| 81 | } |