1
zj
2025-04-30 1e24ff3195adcd0807c110f2c3919bba0d847934
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
package security.internal;
 
import java.util.Iterator;
import java.util.List;
import java.util.Map;
 
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import org.springframework.security.AccessDecisionManager;
 
import kernel.util.StringUtils;
import security.Constants;
import security.util.AuthenticationUtil;
 
public class SecurityResourceProcessorImpl implements SecurityResourceProcessor {
 
    private static final Logger logger=LoggerFactory.getLogger(SecurityResourceProcessorImpl.class);
 
    private SecurityAuthoritiesHolder securityAuthoritiesHolder;
 
    private AccessDecisionManager accessDecisionManager;
 
    public boolean isResourceAccessible(String resource, List<String> roles) {
        return isResourceAccessible(resource, Constants.RESTYPE_OPERATION, roles);
    }
 
    public boolean isResourceAccessible(String resource, String type, List<String> roles) {
        if (StringUtils.isNullOrEmpty(resource)) {
            return true;
        }
        logger.debug("resource[" + resource + "]");
        // URL资源串,逗号相隔的角色串
        Map<String, String> operationAuthorities = securityAuthoritiesHolder.loadAuthorities(type);
        // 角色串
        String authorities = null;
        for (Iterator<Map.Entry<String, String>> iter = operationAuthorities.entrySet().iterator(); iter.hasNext();) {
            Map.Entry<String, String> entry = iter.next();
            String operation = entry.getKey();
            if (resource.equals(operation)) {
                authorities = entry.getValue();
                break;
            }
 
        }
 
        return isRoleExist(authorities, roles);
 
//        
//        ConfigAttributeDefinition attr = AuthenticationUtil.getCadByAuthorities(authorities);
//        if (attr != null) {
//            Authentication authenticated = SecurityAppUserHolder.getAuthentication();
//            try {
//                accessDecisionManager.decide(authenticated, null, attr);
//                return true;
//            } catch (AccessDeniedException accessDeniedException) {
//                return false;
//            }
//        }
//        return true;
 
    }
    
    
 
    @Override
    public boolean isUrlAccessible(String servletPath, List<String> roles) {
        if (StringUtils.isNullOrEmpty(servletPath)) {
            return true;
        }
        
        Map<String, String> urlAuthorities = this.securityAuthoritiesHolder.loadAuthorities(Constants.RESTYPE_URL);
        // 得到该URL允许的角色串
        String authorities = AuthenticationUtil.resourceMatches(urlAuthorities, servletPath);
        
        // 如果为空,该资源没有被定义
        if (StringUtils.isNullOrEmpty(authorities) ) {
            // 是否保护所有资源
            if (AuthenticationUtil.IS_PROTECT_ALL_RESOURCE) {
                 return false;
            }
            else {
                // 返回null,资源不被保护
               
                return true;
            }
        }
        
        return isRoleExist(authorities, roles);
    }
 
    @Override
    public boolean isRolesAccessible(String verifyroles, List<String> roles) {
        return isRoleExist(verifyroles, roles);
    }
 
    public boolean isRoleExist(String authorities, List<String> roles) {
        if (StringUtils.isNullOrEmpty(authorities)) {
            return false;
        }
        String[] arrty = authorities.split(",");
        for (int i = 0; i < arrty.length; i++) {
            for (int j = 0; j < roles.size(); j++) {
                if (arrty[i].equals(roles.get(j))) {
                    return true;
                }
            }
 
        }
        return false;
    }
    
    
 
    public void setAccessDecisionManager(AccessDecisionManager accessDecisionManager) {
        this.accessDecisionManager = accessDecisionManager;
    }
 
    public void setSecurityAuthoritiesHolder(SecurityAuthoritiesHolder securityAuthoritiesHolder) {
        this.securityAuthoritiesHolder = securityAuthoritiesHolder;
    }
 
 
}