Skip to main content
summaryrefslogtreecommitdiffstats
blob: 88b5331f12d8143f9e4964b7d2ab24643d7fe425 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
//
//  ========================================================================
//  Copyright (c) 1995-2016 Mort Bay Consulting Pty. Ltd.
//  ------------------------------------------------------------------------
//  All rights reserved. This program and the accompanying materials
//  are made available under the terms of the Eclipse Public License v1.0
//  and Apache License v2.0 which accompanies this distribution.
//
//      The Eclipse Public License is available at
//      http://www.eclipse.org/legal/epl-v10.html
//
//      The Apache License v2.0 is available at
//      http://www.opensource.org/licenses/apache2.0.php
//
//  You may elect to redistribute this code under either of these licenses.
//  ========================================================================
//

package org.eclipse.jetty.jaas;

import java.security.Principal;
import java.security.acl.Group;
import java.util.Enumeration;


/* ---------------------------------------------------- */
/** StrictRoleCheckPolicy
 * <p>Enforces that if a runAsRole is present, then the
 * role to check must be the same as that runAsRole and
 * the set of static roles is ignored.
 * 
 *
 * 
 * @org.apache.xbean.XBean description ="Check only topmost role in stack of roles for user"
 */
public class StrictRoleCheckPolicy implements RoleCheckPolicy
{

    public boolean checkRole (String roleName, Principal runAsRole, Group roles)
    {
        //check if this user has had any temporary role pushed onto
        //them. If so, then only check if the user has that role.
        if (runAsRole != null)
        {
            return (roleName.equals(runAsRole.getName()));
        }
        else
        {
            if (roles == null)
                return false;
            Enumeration<? extends Principal> rolesEnum = roles.members();
            boolean found = false;
            while (rolesEnum.hasMoreElements() && !found)
            {
                Principal p = (Principal)rolesEnum.nextElement();
                found = roleName.equals(p.getName());
            }
            return found;
        }
        
    }
    
}

Back to the top