Interface AuthorizationManager<T>

All Known Implementing Classes:
AuthenticatedAuthorizationManager, AuthorityAuthorizationManager

public interface AuthorizationManager<T>

Decides whether an authentication may reach something: for a request rule, a RequestAuthorizationContext.

auth.requestMatchers("/accounts/{owner}/**").access((authentication, context) ->
        new AuthorizationDecision(context.getVariables().get("owner")
                .equals(authentication.get().getName())));
  • Method Summary

    Modifier and Type
    Method
    Description
    check(Supplier<Authentication> authentication, T object)
    The decision; null abstains, which a request rule reads as granted.
  • Method Details

    • check

      AuthorizationDecision check(Supplier<Authentication> authentication, T object)
      The decision; null abstains, which a request rule reads as granted.
      Parameters:
      authentication - who is asking, looked up only when the rule needs it