SEC-2031: PreInvocationAuthorizationAdviceVoter supports subclasses

This commit is contained in:
Rob Winch 2012-10-07 11:55:35 -05:00
parent 72aecaff05
commit f3b143f677
2 changed files with 42 additions and 1 deletions

View File

@ -35,7 +35,7 @@ public class PreInvocationAuthorizationAdviceVoter implements AccessDecisionVote
}
public boolean supports(Class<?> clazz) {
return clazz.isAssignableFrom(MethodInvocation.class);
return MethodInvocation.class.isAssignableFrom(clazz);
}
public int vote(Authentication authentication, MethodInvocation method, Collection<ConfigAttribute> attributes) {

View File

@ -0,0 +1,41 @@
package org.springframework.security.access.prepost;
import static org.junit.Assert.assertTrue;
import org.aopalliance.intercept.MethodInvocation;
import org.junit.Before;
import org.junit.Test;
import org.junit.runner.RunWith;
import org.mockito.Mock;
import org.mockito.runners.MockitoJUnitRunner;
import org.springframework.aop.ProxyMethodInvocation;
import org.springframework.security.access.intercept.aspectj.MethodInvocationAdapter;
@RunWith(MockitoJUnitRunner.class)
public class PreInvocationAuthorizationAdviceVoterTests {
@Mock
private PreInvocationAuthorizationAdvice authorizationAdvice;
private PreInvocationAuthorizationAdviceVoter voter;
@Before
public void setUp() {
voter = new PreInvocationAuthorizationAdviceVoter(authorizationAdvice);
}
@Test
public void supportsMethodInvocation() {
assertTrue(voter.supports(MethodInvocation.class));
}
// SEC-2031
@Test
public void supportsProxyMethodInvocation() {
assertTrue(voter.supports(ProxyMethodInvocation.class));
}
@Test
public void supportsMethodInvocationAdapter() {
assertTrue(voter.supports(MethodInvocationAdapter.class));
}
}