Package org.apache.struts2.ognl
Class SecurityMemberAccess
java.lang.Object
org.apache.struts2.ognl.SecurityMemberAccess
- All Implemented Interfaces:
ognl.MemberAccess
Allows access decisions to be made on the basis of whether a member is static or not.
Also blocks or allows access to properties.
-
Constructor Summary
ConstructorsConstructorDescriptionSecurityMemberAccess(ProviderAllowlist providerAllowlist, ThreadAllowlist threadAllowlist) -
Method Summary
Modifier and TypeMethodDescriptionprotected booleancheckAllowlist(Object target, Member member) protected booleancheckDefaultPackageAccess(Object target, Member member) Blocks access to classes in the default (unnamed) package.protected booleancheckExclusionList(Object target, Member member) protected booleancheckProxyMemberAccess(Object target, Member member) protected booleancheckProxyObjectAccess(Object target) protected booleancheckPublicMemberAccess(Member member) Check access for public members (via modifiers)protected booleancheckStaticFieldAccess(Member member) Check access for static field (via modifiers).protected booleancheckStaticMethodAccess(Member member) Check access for static method (via modifiers).protected booleanisAcceptableProperty(String name) protected booleanisAccepted(String paramName) booleanisAccessible(ognl.OgnlContext context, Object target, Member member, String propertyName) protected booleanisClassAllowlisted(Class<?> clazz) static booleanisClassBelongsToPackages(Class<?> clazz, Set<String> matchingPackages) protected booleanisClassExcluded(Class<?> clazz) protected booleanisExcluded(String paramName) protected booleanisExcludedPackageNamePatterns(Class<?> clazz) protected booleanisExcludedPackageNames(Class<?> clazz) protected booleanisPackageExcluded(Class<?> clazz) voidvoidsetProxyService(ProxyService proxyService) static StringtoPackageName(Class<?> clazz) voiduseAcceptProperties(Set<Pattern> acceptedProperties) voiduseAllowlistClasses(String commaDelimitedClasses) Deprecated, for removal: This API element is subject to removal in a future version.voiduseAllowlistPackageNames(String commaDelimitedPackageNames) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig.voiduseAllowStaticFieldAccess(String allowStaticFieldAccess) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig.voiduseConfig(SecurityMemberAccessConfig config) Copies the shared, already-parsed configuration into this instance.voiduseDisallowDefaultPackageAccess(String disallowDefaultPackageAccess) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig.voiduseDisallowProxyMemberAccess(String disallowProxyMemberAccess) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig.voiduseDisallowProxyObjectAccess(String disallowProxyObjectAccess) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig.voiduseEnforceAllowlistEnabled(String enforceAllowlistEnabled) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig.voiduseExcludedClasses(String commaDelimitedClasses) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig.voiduseExcludedPackageExemptClasses(String commaDelimitedClasses) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig.voiduseExcludedPackageNamePatterns(String commaDelimitedPackagePatterns) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig.voiduseExcludedPackageNames(String commaDelimitedPackageNames) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig.voiduseExcludeProperties(Set<Pattern> excludeProperties)
-
Constructor Details
-
SecurityMemberAccess
-
-
Method Details
-
setProxyService
-
useConfig
Copies the shared, already-parsed configuration into this instance. This is the only injected member that touches the configuration fields, so the unspecified order in which the container iteratesgetDeclaredMethods()cannot affect the result.- Since:
- Struts 7.4.0
-
setup
- Specified by:
setupin interfaceognl.MemberAccess
-
restore
public void restore(ognl.OgnlContext context, Object target, Member member, String propertyName, Object state) - Specified by:
restorein interfaceognl.MemberAccess
-
isAccessible
public boolean isAccessible(ognl.OgnlContext context, Object target, Member member, String propertyName) - Specified by:
isAccessiblein interfaceognl.MemberAccess
-
checkAllowlist
- Returns:
trueif member access is allowed
-
isClassAllowlisted
-
checkExclusionList
- Returns:
trueif member access is allowed
-
checkDefaultPackageAccess
Blocks access to classes in the default (unnamed) package.The emptiness of
toPackageName(Class)is the same test as thegetPackage() == null || getPackage().getName().isEmpty()form this replaced, for every class shape:getPackage()is null for arrays, primitives andvoid, and names the unnamed package with the empty string, all of whichtoPackageNamereports as empty. It avoids thegetPackage()lookup through the defining classloader's package map, which ran twice per class here. See WW-5677.- Returns:
trueif member access is allowed
-
checkProxyObjectAccess
- Returns:
trueif proxy object access is allowed
-
checkProxyMemberAccess
- Returns:
trueif proxy member access is allowed
-
checkStaticMethodAccess
Check access for static method (via modifiers).Note: For non-static members, the result is always true.
- Returns:
trueif member access is allowed
-
checkStaticFieldAccess
Check access for static field (via modifiers).Note: For non-static members, the result is always true.
- Returns:
trueif member access is allowed
-
checkPublicMemberAccess
Check access for public members (via modifiers)- Returns:
trueif member access is allowed
-
isPackageExcluded
-
toPackageName
-
isExcludedPackageNamePatterns
-
isExcludedPackageNames
-
isClassBelongsToPackages
-
isClassExcluded
-
isAcceptableProperty
- Returns:
trueif member access is allowed
-
isAccepted
-
isExcluded
-
useExcludeProperties
-
useAcceptProperties
-
useAllowStaticFieldAccess
@Deprecated(since="7.4.0", forRemoval=true) public void useAllowStaticFieldAccess(String allowStaticFieldAccess) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter. -
useExcludedClasses
@Deprecated(since="7.4.0", forRemoval=true) public void useExcludedClasses(String commaDelimitedClasses) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter. -
useExcludedPackageNamePatterns
@Deprecated(since="7.4.0", forRemoval=true) public void useExcludedPackageNamePatterns(String commaDelimitedPackagePatterns) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter. -
useExcludedPackageNames
@Deprecated(since="7.4.0", forRemoval=true) public void useExcludedPackageNames(String commaDelimitedPackageNames) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter. -
useExcludedPackageExemptClasses
@Deprecated(since="7.4.0", forRemoval=true) public void useExcludedPackageExemptClasses(String commaDelimitedClasses) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter. -
useEnforceAllowlistEnabled
@Deprecated(since="7.4.0", forRemoval=true) public void useEnforceAllowlistEnabled(String enforceAllowlistEnabled) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter. -
useAllowlistClasses
@Deprecated(since="7.4.0", forRemoval=true) public void useAllowlistClasses(String commaDelimitedClasses) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter. -
useAllowlistPackageNames
@Deprecated(since="7.4.0", forRemoval=true) public void useAllowlistPackageNames(String commaDelimitedPackageNames) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter. -
useDisallowProxyObjectAccess
@Deprecated(since="7.4.0", forRemoval=true) public void useDisallowProxyObjectAccess(String disallowProxyObjectAccess) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter. -
useDisallowProxyMemberAccess
@Deprecated(since="7.4.0", forRemoval=true) public void useDisallowProxyMemberAccess(String disallowProxyMemberAccess) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter. -
useDisallowDefaultPackageAccess
@Deprecated(since="7.4.0", forRemoval=true) public void useDisallowDefaultPackageAccess(String disallowDefaultPackageAccess) Deprecated, for removal: This API element is subject to removal in a future version.since 7.4.0, configuration is parsed once per container bySecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.
-
SecurityMemberAccessConfig.