【发布时间】:2012-09-03 13:20:01
【问题描述】:
我对 AOP 有点陌生,对我面临的问题感到困惑。我有注释@AuthorizeUser,它作用于表示层上的方法。我需要检查用户是否有权执行该方法。这是AuthorizeUserAspect 的代码:
@Aspect
public class AuthorizeUserAspect {
@AuthoWired
private UserService service;
@Before(value = "@annotation(com.company.annotation.AuthorizeUser)")
public void isAuthorized(JoinPoint jp) {
// Check if the user has permission or not
// executing some Service Layer services and
// Persistence Layer, corresponding to that
service.checkUser();
// Is there a way I can make this method Conditional. something like:
if ( /* User has permission */ ) {
// do nothing, so the method will be executed after this
}
else {
// 1) Prevent the Method to be executed [and/or]
// 2) Pass some Parameters to the method for checking [and/or]
// 3) Execute another method on that class [e.g showAccessDenied()]
}
}
}
有点类似于这个问题Spring MVC + Before Advice check security。但它建议返回一些字符串(即“不好”)。我的应用程序中有两种类型的 UI(Struts 和 Jersey),因此会有两种返回类型(分别为 String 和 Response)。所以我想这可能不是最好的方法。
如果您能告诉我一个解决方法,我将非常高兴。
这是不是一个好方法?
【问题讨论】:
标签: java spring security aspectj spring-aop