All Downloads are FREE. Search and download functionalities are using the official Maven repository.

com.digitalchina.platform.security.auth.CustomUrlVoter Maven / Gradle / Ivy

The newest version!
package com.digitalchina.platform.security.auth;

import com.digitalchina.platform.security.properties.SecureProperties;
import org.apache.log4j.Logger;
import org.springframework.security.access.AccessDecisionVoter;
import org.springframework.security.access.ConfigAttribute;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.GrantedAuthority;

import java.util.Collection;

/**
 * URL授权器
 *
 * @author root
 */
public class CustomUrlVoter implements AccessDecisionVoter {
    Logger logger = Logger.getLogger(CustomUrlVoter.class);

    SecureProperties secureProperties;

    private String ROLE_SUFFIX_DO = ".do";
    private String ROLE_SUFFIX_JSON = ".json";
    private String ROLE_SUFFIX_HTML = ".html";

    public int vote(Authentication authentication, Object object, Collection attributes) {
        Object principal = authentication.getPrincipal();
        if (principal != null) {
            if ("anonymousUser".equals(principal)) {
                return ACCESS_DENIED;
            }
        }

        int result = ACCESS_ABSTAIN;
        Collection authorities = authentication.getAuthorities();

        for (ConfigAttribute attribute : attributes) {
            if (this.supports(attribute)) {
                result = ACCESS_DENIED;
                for (GrantedAuthority authority : authorities) {
                    if (attribute.getAttribute().equals(authority.getAuthority())) {
                        return ACCESS_GRANTED;
                    }
                }
            }
        }

        if (result == -1) {
            System.out.println(attributes.toString());
        }

        return result;
    }


    public boolean supports(ConfigAttribute attribute) {
        if ((attribute.getAttribute() != null)
                && (attribute.getAttribute().toLowerCase().endsWith(ROLE_SUFFIX_DO) || attribute.getAttribute().toLowerCase().endsWith(ROLE_SUFFIX_JSON) || attribute.getAttribute().toLowerCase().endsWith(ROLE_SUFFIX_HTML))) {
            return true;
        } else {
            logger.error("请求url格式非法,必须以.json,.do,.html结尾!");
            return false;
        }
        //return true;
    }

    public boolean supports(Class clazz) {
        return true;
    }

    public SecureProperties getSecureProperties() {
        return secureProperties;
    }

    public void setSecureProperties(SecureProperties secureProperties) {
        this.secureProperties = secureProperties;
    }
}