blob: fab44d7c4965229997051461a7510e6ab0107f90 [file] [log] [blame]
<!DOCTYPE HTML>
<html lang="en">
<head>
<title>Source code</title>
<link rel="stylesheet" type="text/css" href="../../../../../../../stylesheet.css" title="Style">
</head>
<body>
<main role="main">
<div class="sourceContainer">
<pre><span class="sourceLineNo">001</span><a id="line.1">/*</a>
<span class="sourceLineNo">002</span><a id="line.2"> * Licensed to the Apache Software Foundation (ASF) under one</a>
<span class="sourceLineNo">003</span><a id="line.3"> * or more contributor license agreements. See the NOTICE file</a>
<span class="sourceLineNo">004</span><a id="line.4"> * distributed with this work for additional information</a>
<span class="sourceLineNo">005</span><a id="line.5"> * regarding copyright ownership. The ASF licenses this file</a>
<span class="sourceLineNo">006</span><a id="line.6"> * to you under the Apache License, Version 2.0 (the</a>
<span class="sourceLineNo">007</span><a id="line.7"> * "License"); you may not use this file except in compliance</a>
<span class="sourceLineNo">008</span><a id="line.8"> * with the License. You may obtain a copy of the License at</a>
<span class="sourceLineNo">009</span><a id="line.9"> *</a>
<span class="sourceLineNo">010</span><a id="line.10"> * http://www.apache.org/licenses/LICENSE-2.0</a>
<span class="sourceLineNo">011</span><a id="line.11"> *</a>
<span class="sourceLineNo">012</span><a id="line.12"> * Unless required by applicable law or agreed to in writing,</a>
<span class="sourceLineNo">013</span><a id="line.13"> * software distributed under the License is distributed on an</a>
<span class="sourceLineNo">014</span><a id="line.14"> * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY</a>
<span class="sourceLineNo">015</span><a id="line.15"> * KIND, either express or implied. See the License for the</a>
<span class="sourceLineNo">016</span><a id="line.16"> * specific language governing permissions and limitations</a>
<span class="sourceLineNo">017</span><a id="line.17"> * under the License.</a>
<span class="sourceLineNo">018</span><a id="line.18"> */</a>
<span class="sourceLineNo">019</span><a id="line.19">package org.apache.shiro.web.filter.authz;</a>
<span class="sourceLineNo">020</span><a id="line.20"></a>
<span class="sourceLineNo">021</span><a id="line.21">import org.apache.shiro.subject.Subject;</a>
<span class="sourceLineNo">022</span><a id="line.22">import org.apache.shiro.util.StringUtils;</a>
<span class="sourceLineNo">023</span><a id="line.23">import org.apache.shiro.web.filter.AccessControlFilter;</a>
<span class="sourceLineNo">024</span><a id="line.24">import org.apache.shiro.web.util.WebUtils;</a>
<span class="sourceLineNo">025</span><a id="line.25"></a>
<span class="sourceLineNo">026</span><a id="line.26">import javax.servlet.ServletRequest;</a>
<span class="sourceLineNo">027</span><a id="line.27">import javax.servlet.ServletResponse;</a>
<span class="sourceLineNo">028</span><a id="line.28">import javax.servlet.http.HttpServletResponse;</a>
<span class="sourceLineNo">029</span><a id="line.29">import java.io.IOException;</a>
<span class="sourceLineNo">030</span><a id="line.30"></a>
<span class="sourceLineNo">031</span><a id="line.31">/**</a>
<span class="sourceLineNo">032</span><a id="line.32"> * Superclass for authorization-related filters. If an request is unauthorized, response handling is delegated to the</a>
<span class="sourceLineNo">033</span><a id="line.33"> * {@link #onAccessDenied(javax.servlet.ServletRequest, javax.servlet.ServletResponse) onAccessDenied} method, which</a>
<span class="sourceLineNo">034</span><a id="line.34"> * provides reasonable handling for most applications.</a>
<span class="sourceLineNo">035</span><a id="line.35"> *</a>
<span class="sourceLineNo">036</span><a id="line.36"> * @see #onAccessDenied(javax.servlet.ServletRequest, javax.servlet.ServletResponse)</a>
<span class="sourceLineNo">037</span><a id="line.37"> * @since 0.9</a>
<span class="sourceLineNo">038</span><a id="line.38"> */</a>
<span class="sourceLineNo">039</span><a id="line.39">public abstract class AuthorizationFilter extends AccessControlFilter {</a>
<span class="sourceLineNo">040</span><a id="line.40"></a>
<span class="sourceLineNo">041</span><a id="line.41"> /**</a>
<span class="sourceLineNo">042</span><a id="line.42"> * The URL to which users should be redirected if they are denied access to an underlying path or resource,</a>
<span class="sourceLineNo">043</span><a id="line.43"> * {@code null} by default which will issue a raw {@link HttpServletResponse#SC_UNAUTHORIZED} response</a>
<span class="sourceLineNo">044</span><a id="line.44"> * (401 Unauthorized).</a>
<span class="sourceLineNo">045</span><a id="line.45"> */</a>
<span class="sourceLineNo">046</span><a id="line.46"> private String unauthorizedUrl;</a>
<span class="sourceLineNo">047</span><a id="line.47"></a>
<span class="sourceLineNo">048</span><a id="line.48"> /**</a>
<span class="sourceLineNo">049</span><a id="line.49"> * Returns the URL to which users should be redirected if they are denied access to an underlying path or resource,</a>
<span class="sourceLineNo">050</span><a id="line.50"> * or {@code null} if a raw {@link HttpServletResponse#SC_UNAUTHORIZED} response should be issued (401 Unauthorized).</a>
<span class="sourceLineNo">051</span><a id="line.51"> * &lt;p/&gt;</a>
<span class="sourceLineNo">052</span><a id="line.52"> * The default is {@code null}, ensuring default web server behavior. Override this default by calling the</a>
<span class="sourceLineNo">053</span><a id="line.53"> * {@link #setUnauthorizedUrl(String) setUnauthorizedUrl} method with a meaningful path within your application</a>
<span class="sourceLineNo">054</span><a id="line.54"> * if you would like to show the user a 'nice' page in the event of unauthorized access.</a>
<span class="sourceLineNo">055</span><a id="line.55"> *</a>
<span class="sourceLineNo">056</span><a id="line.56"> * @return the URL to which users should be redirected if they are denied access to an underlying path or resource,</a>
<span class="sourceLineNo">057</span><a id="line.57"> * or {@code null} if a raw {@link HttpServletResponse#SC_UNAUTHORIZED} response should be issued (401 Unauthorized).</a>
<span class="sourceLineNo">058</span><a id="line.58"> */</a>
<span class="sourceLineNo">059</span><a id="line.59"> public String getUnauthorizedUrl() {</a>
<span class="sourceLineNo">060</span><a id="line.60"> return unauthorizedUrl;</a>
<span class="sourceLineNo">061</span><a id="line.61"> }</a>
<span class="sourceLineNo">062</span><a id="line.62"></a>
<span class="sourceLineNo">063</span><a id="line.63"> /**</a>
<span class="sourceLineNo">064</span><a id="line.64"> * Sets the URL to which users should be redirected if they are denied access to an underlying path or resource.</a>
<span class="sourceLineNo">065</span><a id="line.65"> * &lt;p/&gt;</a>
<span class="sourceLineNo">066</span><a id="line.66"> * If the value is {@code null} a raw {@link HttpServletResponse#SC_UNAUTHORIZED} response will</a>
<span class="sourceLineNo">067</span><a id="line.67"> * be issued (401 Unauthorized), retaining default web server behavior.</a>
<span class="sourceLineNo">068</span><a id="line.68"> * &lt;p/&gt;</a>
<span class="sourceLineNo">069</span><a id="line.69"> * Unless overridden by calling this method, the default value is {@code null}. If desired, you can specify a</a>
<span class="sourceLineNo">070</span><a id="line.70"> * meaningful path within your application if you would like to show the user a 'nice' page in the event of</a>
<span class="sourceLineNo">071</span><a id="line.71"> * unauthorized access.</a>
<span class="sourceLineNo">072</span><a id="line.72"> *</a>
<span class="sourceLineNo">073</span><a id="line.73"> * @param unauthorizedUrl the URL to which users should be redirected if they are denied access to an underlying</a>
<span class="sourceLineNo">074</span><a id="line.74"> * path or resource, or {@code null} to a ensure raw {@link HttpServletResponse#SC_UNAUTHORIZED} response is</a>
<span class="sourceLineNo">075</span><a id="line.75"> * issued (401 Unauthorized).</a>
<span class="sourceLineNo">076</span><a id="line.76"> */</a>
<span class="sourceLineNo">077</span><a id="line.77"> public void setUnauthorizedUrl(String unauthorizedUrl) {</a>
<span class="sourceLineNo">078</span><a id="line.78"> this.unauthorizedUrl = unauthorizedUrl;</a>
<span class="sourceLineNo">079</span><a id="line.79"> }</a>
<span class="sourceLineNo">080</span><a id="line.80"></a>
<span class="sourceLineNo">081</span><a id="line.81"> /**</a>
<span class="sourceLineNo">082</span><a id="line.82"> * Handles the response when access has been denied. It behaves as follows:</a>
<span class="sourceLineNo">083</span><a id="line.83"> * &lt;ul&gt;</a>
<span class="sourceLineNo">084</span><a id="line.84"> * &lt;li&gt;If the {@code Subject} is unknown&lt;sup&gt;&lt;a href="#known"&gt;[1]&lt;/a&gt;&lt;/sup&gt;:</a>
<span class="sourceLineNo">085</span><a id="line.85"> * &lt;ol&gt;&lt;li&gt;The incoming request will be saved and they will be redirected to the login page for authentication</a>
<span class="sourceLineNo">086</span><a id="line.86"> * (via the {@link #saveRequestAndRedirectToLogin(javax.servlet.ServletRequest, javax.servlet.ServletResponse)}</a>
<span class="sourceLineNo">087</span><a id="line.87"> * method).&lt;/li&gt;</a>
<span class="sourceLineNo">088</span><a id="line.88"> * &lt;li&gt;Once successfully authenticated, they will be redirected back to the originally attempted page.&lt;/li&gt;&lt;/ol&gt;</a>
<span class="sourceLineNo">089</span><a id="line.89"> * &lt;/li&gt;</a>
<span class="sourceLineNo">090</span><a id="line.90"> * &lt;li&gt;If the Subject is known:&lt;/li&gt;</a>
<span class="sourceLineNo">091</span><a id="line.91"> * &lt;ol&gt;</a>
<span class="sourceLineNo">092</span><a id="line.92"> * &lt;li&gt;The HTTP {@link HttpServletResponse#SC_UNAUTHORIZED} header will be set (401 Unauthorized)&lt;/li&gt;</a>
<span class="sourceLineNo">093</span><a id="line.93"> * &lt;li&gt;If the {@link #getUnauthorizedUrl() unauthorizedUrl} has been configured, a redirect will be issued to that</a>
<span class="sourceLineNo">094</span><a id="line.94"> * URL. Otherwise the 401 response is rendered normally&lt;/li&gt;</a>
<span class="sourceLineNo">095</span><a id="line.95"> * &lt;/ul&gt;</a>
<span class="sourceLineNo">096</span><a id="line.96"> * &lt;code&gt;&lt;a name="known"&gt;[1]&lt;/a&gt;&lt;/code&gt;: A {@code Subject} is 'known' when</a>
<span class="sourceLineNo">097</span><a id="line.97"> * &lt;code&gt;subject.{@link org.apache.shiro.subject.Subject#getPrincipal() getPrincipal()}&lt;/code&gt; is not {@code null},</a>
<span class="sourceLineNo">098</span><a id="line.98"> * which implicitly means that the subject is either currently authenticated or they have been remembered via</a>
<span class="sourceLineNo">099</span><a id="line.99"> * 'remember me' services.</a>
<span class="sourceLineNo">100</span><a id="line.100"> *</a>
<span class="sourceLineNo">101</span><a id="line.101"> * @param request the incoming &lt;code&gt;ServletRequest&lt;/code&gt;</a>
<span class="sourceLineNo">102</span><a id="line.102"> * @param response the outgoing &lt;code&gt;ServletResponse&lt;/code&gt;</a>
<span class="sourceLineNo">103</span><a id="line.103"> * @return {@code false} always for this implementation.</a>
<span class="sourceLineNo">104</span><a id="line.104"> * @throws IOException if there is any servlet error.</a>
<span class="sourceLineNo">105</span><a id="line.105"> */</a>
<span class="sourceLineNo">106</span><a id="line.106"> protected boolean onAccessDenied(ServletRequest request, ServletResponse response) throws IOException {</a>
<span class="sourceLineNo">107</span><a id="line.107"></a>
<span class="sourceLineNo">108</span><a id="line.108"> Subject subject = getSubject(request, response);</a>
<span class="sourceLineNo">109</span><a id="line.109"> // If the subject isn't identified, redirect to login URL</a>
<span class="sourceLineNo">110</span><a id="line.110"> if (subject.getPrincipal() == null) {</a>
<span class="sourceLineNo">111</span><a id="line.111"> saveRequestAndRedirectToLogin(request, response);</a>
<span class="sourceLineNo">112</span><a id="line.112"> } else {</a>
<span class="sourceLineNo">113</span><a id="line.113"> // If subject is known but not authorized, redirect to the unauthorized URL if there is one</a>
<span class="sourceLineNo">114</span><a id="line.114"> // If no unauthorized URL is specified, just return an unauthorized HTTP status code</a>
<span class="sourceLineNo">115</span><a id="line.115"> String unauthorizedUrl = getUnauthorizedUrl();</a>
<span class="sourceLineNo">116</span><a id="line.116"> //SHIRO-142 - ensure that redirect _or_ error code occurs - both cannot happen due to response commit:</a>
<span class="sourceLineNo">117</span><a id="line.117"> if (StringUtils.hasText(unauthorizedUrl)) {</a>
<span class="sourceLineNo">118</span><a id="line.118"> WebUtils.issueRedirect(request, response, unauthorizedUrl);</a>
<span class="sourceLineNo">119</span><a id="line.119"> } else {</a>
<span class="sourceLineNo">120</span><a id="line.120"> WebUtils.toHttp(response).sendError(HttpServletResponse.SC_UNAUTHORIZED);</a>
<span class="sourceLineNo">121</span><a id="line.121"> }</a>
<span class="sourceLineNo">122</span><a id="line.122"> }</a>
<span class="sourceLineNo">123</span><a id="line.123"> return false;</a>
<span class="sourceLineNo">124</span><a id="line.124"> }</a>
<span class="sourceLineNo">125</span><a id="line.125"></a>
<span class="sourceLineNo">126</span><a id="line.126">}</a>
</pre>
</div>
</main>
</body>
</html>