如何在自定义表达式处理程序中获取用户详细信息

时间:2013-05-15 13:18:37

标签: java spring spring-mvc spring-security spring-3

我正在使用自定义安全表达式处理程序并使用spring 3.2.0。这是自定义表达式根类:

public class CustomerPortalSecurityExpressionRoot extends WebSecurityExpressionRoot {

    private static final Log logger = LogFactory.getLog(CustomerPortalSecurityExpressionRoot.class);

    private CustomerPortalPanicService customerPortalPanicService;

    public CustomerPortalSecurityExpressionRoot(Authentication a, FilterInvocation fi) {
        super(a, fi);
    }

    public boolean isPanicking() {
        if (customerPortalPanicService != null) {

            return customerPortalPanicService.isPanicking();
        } else {
            logger.warn("CustomerPortalPanicService is not available.");
            return false;
        }
    }


    public boolean hasGotPermission(String title){


       logger.debug("coming inside has Permission! @public class CustomerPortalSecurityExpressionRoot "+title);
        return true;
    }
    public void setCustomerPortalPanicService(CustomerPortalPanicService customerPortalPanicService) {
        this.customerPortalPanicService = customerPortalPanicService;
    }
}

我在Spring安全配置文件中使用它:

 <http auto-config="true" use-expressions="true" >

        <form-login login-page="/login" login-processing-url="/loginIFM" authentication-failure-url="/login/?login_error=1" username-parameter="username" password-parameter="password" />
        <logout invalidate-session="true" logout-success-url="/" logout-url="/logout_ifm" />

         <expression-handler ref="webSecurityExpressionHandler"/>

        <!-- Rules. -->
        <!--     <intercept-url pattern="/" access="permitAll" /> -->

        <intercept-url pattern="/hardcopy/*" access="isAuthenticated() and hasPermission('tw')" />
    </http>

 <!-- expression custom handler -->
    <b:bean id="webSecurityExpressionHandler" class="no.user.security.DnWebSecurityExpressionHandler" />

使用身份验证管理器进行身份验证,我只想知道如何获取在身份验证后作为JSON响应发布的用户详细信息?我知道PermissionEvaluator中有一个hasPermission事物,但这对我来说更灵活。救命啊!

1 个答案:

答案 0 :(得分:1)

您可以使用SecurityContextHolder.getContext().getAuthentication().getAuthorities()来获取授予当前经过身份验证的用户的权限。