Class SecurityMemberAccess

java.lang.Object
org.apache.struts2.ognl.SecurityMemberAccess
All Implemented Interfaces:
ognl.MemberAccess

public class SecurityMemberAccess extends Object implements ognl.MemberAccess
Allows access decisions to be made on the basis of whether a member is static or not. Also blocks or allows access to properties.
  • Constructor Details

  • Method Details

    • setProxyService

      public void setProxyService(ProxyService proxyService)
    • useConfig

      public void useConfig(SecurityMemberAccessConfig config)
      Copies the shared, already-parsed configuration into this instance. This is the only injected member that touches the configuration fields, so the unspecified order in which the container iterates getDeclaredMethods() cannot affect the result.
      Since:
      Struts 7.4.0
    • setup

      public Object setup(ognl.OgnlContext context, Object target, Member member, String propertyName)
      Specified by:
      setup in interface ognl.MemberAccess
    • restore

      public void restore(ognl.OgnlContext context, Object target, Member member, String propertyName, Object state)
      Specified by:
      restore in interface ognl.MemberAccess
    • isAccessible

      public boolean isAccessible(ognl.OgnlContext context, Object target, Member member, String propertyName)
      Specified by:
      isAccessible in interface ognl.MemberAccess
    • checkAllowlist

      protected boolean checkAllowlist(Object target, Member member)
      Returns:
      true if member access is allowed
    • isClassAllowlisted

      protected boolean isClassAllowlisted(Class<?> clazz)
    • checkExclusionList

      protected boolean checkExclusionList(Object target, Member member)
      Returns:
      true if member access is allowed
    • checkDefaultPackageAccess

      protected boolean checkDefaultPackageAccess(Object target, Member member)
      Blocks access to classes in the default (unnamed) package.

      The emptiness of toPackageName(Class) is the same test as the getPackage() == null || getPackage().getName().isEmpty() form this replaced, for every class shape: getPackage() is null for arrays, primitives and void, and names the unnamed package with the empty string, all of which toPackageName reports as empty. It avoids the getPackage() lookup through the defining classloader's package map, which ran twice per class here. See WW-5677.

      Returns:
      true if member access is allowed
    • checkProxyObjectAccess

      protected boolean checkProxyObjectAccess(Object target)
      Returns:
      true if proxy object access is allowed
    • checkProxyMemberAccess

      protected boolean checkProxyMemberAccess(Object target, Member member)
      Returns:
      true if proxy member access is allowed
    • checkStaticMethodAccess

      protected boolean checkStaticMethodAccess(Member member)
      Check access for static method (via modifiers).

      Note: For non-static members, the result is always true.

      Returns:
      true if member access is allowed
    • checkStaticFieldAccess

      protected boolean checkStaticFieldAccess(Member member)
      Check access for static field (via modifiers).

      Note: For non-static members, the result is always true.

      Returns:
      true if member access is allowed
    • checkPublicMemberAccess

      protected boolean checkPublicMemberAccess(Member member)
      Check access for public members (via modifiers)
      Returns:
      true if member access is allowed
    • isPackageExcluded

      protected boolean isPackageExcluded(Class<?> clazz)
    • toPackageName

      public static String toPackageName(Class<?> clazz)
    • isExcludedPackageNamePatterns

      protected boolean isExcludedPackageNamePatterns(Class<?> clazz)
    • isExcludedPackageNames

      protected boolean isExcludedPackageNames(Class<?> clazz)
    • isClassBelongsToPackages

      public static boolean isClassBelongsToPackages(Class<?> clazz, Set<String> matchingPackages)
    • isClassExcluded

      protected boolean isClassExcluded(Class<?> clazz)
    • isAcceptableProperty

      protected boolean isAcceptableProperty(String name)
      Returns:
      true if member access is allowed
    • isAccepted

      protected boolean isAccepted(String paramName)
    • isExcluded

      protected boolean isExcluded(String paramName)
    • useExcludeProperties

      public void useExcludeProperties(Set<Pattern> excludeProperties)
    • useAcceptProperties

      public void useAcceptProperties(Set<Pattern> acceptedProperties)
    • useAllowStaticFieldAccess

      @Deprecated(since="7.4.0", forRemoval=true) public void useAllowStaticFieldAccess(String allowStaticFieldAccess)
      Deprecated, for removal: This API element is subject to removal in a future version.
      since 7.4.0, configuration is parsed once per container by SecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.
    • useExcludedClasses

      @Deprecated(since="7.4.0", forRemoval=true) public void useExcludedClasses(String commaDelimitedClasses)
      Deprecated, for removal: This API element is subject to removal in a future version.
      since 7.4.0, configuration is parsed once per container by SecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.
    • useExcludedPackageNamePatterns

      @Deprecated(since="7.4.0", forRemoval=true) public void useExcludedPackageNamePatterns(String commaDelimitedPackagePatterns)
      Deprecated, for removal: This API element is subject to removal in a future version.
      since 7.4.0, configuration is parsed once per container by SecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.
    • useExcludedPackageNames

      @Deprecated(since="7.4.0", forRemoval=true) public void useExcludedPackageNames(String commaDelimitedPackageNames)
      Deprecated, for removal: This API element is subject to removal in a future version.
      since 7.4.0, configuration is parsed once per container by SecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.
    • useExcludedPackageExemptClasses

      @Deprecated(since="7.4.0", forRemoval=true) public void useExcludedPackageExemptClasses(String commaDelimitedClasses)
      Deprecated, for removal: This API element is subject to removal in a future version.
      since 7.4.0, configuration is parsed once per container by SecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.
    • useEnforceAllowlistEnabled

      @Deprecated(since="7.4.0", forRemoval=true) public void useEnforceAllowlistEnabled(String enforceAllowlistEnabled)
      Deprecated, for removal: This API element is subject to removal in a future version.
      since 7.4.0, configuration is parsed once per container by SecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.
    • useAllowlistClasses

      @Deprecated(since="7.4.0", forRemoval=true) public void useAllowlistClasses(String commaDelimitedClasses)
      Deprecated, for removal: This API element is subject to removal in a future version.
      since 7.4.0, configuration is parsed once per container by SecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.
    • useAllowlistPackageNames

      @Deprecated(since="7.4.0", forRemoval=true) public void useAllowlistPackageNames(String commaDelimitedPackageNames)
      Deprecated, for removal: This API element is subject to removal in a future version.
      since 7.4.0, configuration is parsed once per container by SecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.
    • useDisallowProxyObjectAccess

      @Deprecated(since="7.4.0", forRemoval=true) public void useDisallowProxyObjectAccess(String disallowProxyObjectAccess)
      Deprecated, for removal: This API element is subject to removal in a future version.
      since 7.4.0, configuration is parsed once per container by SecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.
    • useDisallowProxyMemberAccess

      @Deprecated(since="7.4.0", forRemoval=true) public void useDisallowProxyMemberAccess(String disallowProxyMemberAccess)
      Deprecated, for removal: This API element is subject to removal in a future version.
      since 7.4.0, configuration is parsed once per container by SecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.
    • useDisallowDefaultPackageAccess

      @Deprecated(since="7.4.0", forRemoval=true) public void useDisallowDefaultPackageAccess(String disallowDefaultPackageAccess)
      Deprecated, for removal: This API element is subject to removal in a future version.
      since 7.4.0, configuration is parsed once per container by SecurityMemberAccessConfig. This method still mutates this instance and is retained for tests and existing callers; it will be removed in Struts 8.0.0. The container no longer invokes this setter.