August 2017
Beginner to intermediate
370 pages
8h 37m
English
Once a user is authenticated, the next step is to decide whether the principal is allowed to access the desired resource. Here, Spring Security provides an Authroization component named as AccessDecisionManager. The AccessDecisionManager component provides an API, which decides what takes arguments, such as the Authentication object, a secure object, and a list of security metadata attributes such as one or more roles for taking authorization-related decisions.
Authorization can be achieved using AOP (Spring AOP or AspectJ) advice for deciding whether a method invocation is permitted for the principal having a particular role. Authorization can also be achieved using authorization filters on web ...
Read now
Unlock full access