2013-05-15 19 views
0

我正在使用自定義安全表達式處理程序並使用spring 3.2.0。這是自定義表達式根類:如何在自定義表達式處理程序中獲取用戶詳細信息

public class CustomerPortalSecurityExpressionRoot extends WebSecurityExpressionRoot { 

    private static final Log logger = LogFactory.getLog(CustomerPortalSecurityExpressionRoot.class); 

    private CustomerPortalPanicService customerPortalPanicService; 

    public CustomerPortalSecurityExpressionRoot(Authentication a, FilterInvocation fi) { 
     super(a, fi); 
    } 

    public boolean isPanicking() { 
     if (customerPortalPanicService != null) { 

      return customerPortalPanicService.isPanicking(); 
     } else { 
      logger.warn("CustomerPortalPanicService is not available."); 
      return false; 
     } 
    } 


    public boolean hasGotPermission(String title){ 


     logger.debug("coming inside has Permission! @public class CustomerPortalSecurityExpressionRoot "+title); 
     return true; 
    } 
    public void setCustomerPortalPanicService(CustomerPortalPanicService customerPortalPanicService) { 
     this.customerPortalPanicService = customerPortalPanicService; 
    } 
} 

我使用這種方式在春季安全配置文件:

<http auto-config="true" use-expressions="true" > 

     <form-login login-page="/login" login-processing-url="/loginIFM" authentication-failure-url="/login/?login_error=1" username-parameter="username" password-parameter="password" /> 
     <logout invalidate-session="true" logout-success-url="/" logout-url="/logout_ifm" /> 

     <expression-handler ref="webSecurityExpressionHandler"/> 

     <!-- Rules. --> 
     <!--  <intercept-url pattern="/" access="permitAll" /> --> 

     <intercept-url pattern="/hardcopy/*" access="isAuthenticated() and hasPermission('tw')" /> 
    </http> 

<!-- expression custom handler --> 
    <b:bean id="webSecurityExpressionHandler" class="no.user.security.DnWebSecurityExpressionHandler" /> 

認證所使用的認證經理正在發生,我只是想知道,我如何才能獲得認證後即將作爲JSON響應的用戶詳細信息?我知道PermissionEvaluator中有一個hasPermission,但這對我來說更加靈活。幫幫我!

回答

1

您可以使用SecurityContextHolder.getContext().getAuthentication().getAuthorities()獲取授予當前已通過身份驗證的用戶的權限。

+0

謝謝!我會試一下 :) – Maverick

相關問題