Gemfire JavaDocs
Interface MethodInvocationAuthorizer
-
- All Known Implementing Classes:
ExampleAnnotationBasedMethodInvocationAuthorizer
,JavaBeanAccessorMethodAuthorizer
,RegExMethodAuthorizer
,RestrictedMethodAuthorizer
,UnrestrictedMethodAuthorizer
public interface MethodInvocationAuthorizer
The root interface that should be implemented by method invocation authorizer instances. The authorizer is responsible for determining whether aMethod
is allowed to be executed on a specificObject
instance. Implementations of this interface should provide a no-arg constructor.There are mainly four security risks when allowing users to execute arbitrary methods in OQL, which should be addressed by implementations of this interface:
Java Reflection
: do anything throughObject.getClass()
or similar.Cache Modification
: executeCache
operations (close, get regions, etc.).Region Modification
: executeRegion
operations (destroy, invalidate, etc.).Region Entry Modification
: execute in-place modifications on the region entries.
Implementations of this interface should be thread-safe: multiple threads might be authorizing several method invocations using the same instance at the same time.
-
-
Method Summary
All Methods Instance Methods Abstract Methods Default Methods Modifier and Type Method Description boolean
authorize(java.lang.reflect.Method method, java.lang.Object target)
Executes the authorization logic to determine whether themethod
is allowed to be executed on thetarget
object instance.default void
initialize(Cache cache, java.util.Set<java.lang.String> parameters)
-
-
-
Method Detail
-
initialize
default void initialize(Cache cache, java.util.Set<java.lang.String> parameters)
Initializes the MethodInvocationAuthorizer using aCache
and aSet
ofString
parameters.This method exists to allow user-specified method authorizers to be configured and used at runtime. If this method is not overridden in a user-specified authorizer then that authorizer will not be configurable.
- Parameters:
cache
- theCache
to which the MethodInvocationAuthorizer will belongparameters
- aSet
ofString
that will be used to configure the MethodInvocationAuthorizer
-
authorize
boolean authorize(java.lang.reflect.Method method, java.lang.Object target)
Executes the authorization logic to determine whether themethod
is allowed to be executed on thetarget
object instance.Implementation Note: the query engine will remember whether the method invocation has been already authorized or not for the current query context, so this method will be called once in the lifetime of a query for every new method seen while traversing the objects. Nevertheless, the implementation should be lighting fast as it will be called by the OQL engine in runtime during the query execution.
- Parameters:
method
- theMethod
that should be authorized.target
- theObject
on which theMethod
will be executed.- Returns:
true
if themethod
can be executed on on thetarget
instance,false
otherwise.
-
-