Annotation Type PreAuthorize


@Retention(CLASS) @Target({METHOD,TYPE}) public @interface PreAuthorize

Lets this method -- or every public method of this class -- run only when an expression about the caller holds.

@PreAuthorize("hasRole('ADMIN') or #owner == authentication.name")
public Report read(String owner) { ... }

@PreAuthorize("@documents.canEdit(authentication, #id)")
public void rename(long id, String title) { ... }

A caller who has not signed in gets an InsufficientAuthenticationException, which a chain answers with its sign-in challenge; one who has signed in and is refused gets an AccessDeniedException, which is a 403.

The expression is compiled by the build into plain Java -- there is nothing to interpret at run time -- and a mistake in it is a build error. What it may contain:

  • hasRole('X'), hasAnyRole('X', 'Y'), hasAuthority('X'), hasAnyAuthority('X', 'Y'). A role is the authority ROLE_X.
  • isAuthenticated(), isAnonymous(), isFullyAuthenticated() -- signed in during this session rather than remembered from an earlier one -- isRememberMe(), permitAll and denyAll.
  • and, or, not, also written &&, || and !, and parentheses.
  • authentication.name and principal.username, compared with == or != to a string literal or to a String parameter written #name.
  • A call on a bean, @beanName.method(...), whose arguments are authentication, principal, a parameter #name, or a string, whole number or boolean literal. The method must be one the build can find, visible to this class, and return boolean. The bean is a singleton of the server the calling thread works for.

A parameter is named as the source names it, when the class was compiled with debug information or -parameters, or by a P annotation on it.

Not supported, each refused by the build: hasPermission, returnObject, T(...), property chains such as #dto.owner.id, and the post-invocation and filtering annotations of Spring Security. Put what those would do in a bean method and call it.

An annotation on a method replaces the one on its class. The build rewrites the method itself rather than wrapping the object in a proxy, so the check runs however the method is called: from another bean, from this, on a private method, or on an object built with new. In Spring a call through this skips it. For an Async method the check runs on the caller's thread, before the work is handed off.

A module that uses this needs a SecurityFilterChain bean: without one nobody ever signs in, and the build refuses the annotation.

  • Required Element Summary

    Required Elements
    Modifier and Type
    Required Element
    Description
    The expression.
  • Element Details

    • value

      String value
      The expression.