Annotation Type PreAuthorize
Lets this method -- or every public method of this class -- run only when an expression about the caller holds.
@PreAuthorize("hasRole('ADMIN') or #owner == authentication.name")
public Report read(String owner) { ... }
@PreAuthorize("@documents.canEdit(authentication, #id)")
public void rename(long id, String title) { ... }
A caller who has not signed in gets an
InsufficientAuthenticationException, which
a chain answers with its sign-in challenge; one who has signed in and is
refused gets an AccessDeniedException,
which is a 403.
The expression is compiled by the build into plain Java -- there is nothing to interpret at run time -- and a mistake in it is a build error. What it may contain:
hasRole('X'),hasAnyRole('X', 'Y'),hasAuthority('X'),hasAnyAuthority('X', 'Y'). A role is the authorityROLE_X.isAuthenticated(),isAnonymous(),isFullyAuthenticated()-- signed in during this session rather than remembered from an earlier one --isRememberMe(),permitAllanddenyAll.and,or,not, also written&&,||and!, and parentheses.authentication.nameandprincipal.username, compared with==or!=to a string literal or to aStringparameter written#name.- A call on a bean,
@beanName.method(...), whose arguments areauthentication,principal, a parameter#name, or a string, whole number or boolean literal. The method must be one the build can find, visible to this class, and returnboolean. The bean is a singleton of the server the calling thread works for.
A parameter is named as the source names it, when the class was compiled
with debug information or -parameters, or by a P annotation on it.
Not supported, each refused by the build: hasPermission, returnObject,
T(...), property chains such as #dto.owner.id, and the post-invocation
and filtering annotations of Spring Security. Put what those would do in a
bean method and call it.
An annotation on a method replaces the one on its class. The build rewrites
the method itself rather than wrapping the object in a proxy, so the check
runs however the method is called: from another bean, from this, on a
private method, or on an object built with new. In Spring a call through
this skips it. For an Async method the check runs on the caller's
thread, before the work is handed off.
A module that uses this needs a
SecurityFilterChain bean: without one
nobody ever signs in, and the build refuses the annotation.
-
Required Element Summary
Required Elements
-
Element Details
-
value
String valueThe expression.
-