001 /*
002 * Licensed to the Apache Software Foundation (ASF) under one
003 * or more contributor license agreements. See the NOTICE file
004 * distributed with this work for additional information
005 * regarding copyright ownership. The ASF licenses this file
006 * to you under the Apache License, Version 2.0 (the
007 * "License"); you may not use this file except in compliance
008 * with the License. You may obtain a copy of the License at
009 *
010 * http://www.apache.org/licenses/LICENSE-2.0
011 *
012 * Unless required by applicable law or agreed to in writing,
013 * software distributed under the License is distributed on an
014 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
015 * KIND, either express or implied. See the License for the
016 * specific language governing permissions and limitations
017 * under the License.
018 */
019 package org.apache.shiro.authz.aop;
020
021 import java.lang.annotation.Annotation;
022
023 import org.apache.shiro.authz.UnauthenticatedException;
024 import org.apache.shiro.authz.annotation.RequiresAuthentication;
025
026
027 /**
028 * Handles {@link RequiresAuthentication RequiresAuthentication} annotations and ensures the calling subject is
029 * authenticated before allowing access.
030 *
031 * @author Les Hazlewood
032 * @since 0.9.0
033 */
034 public class AuthenticatedAnnotationHandler extends AuthorizingAnnotationHandler {
035
036 /**
037 * Default no-argument constructor that ensures this handler to process
038 * {@link org.apache.shiro.authz.annotation.RequiresAuthentication RequiresAuthentication} annotations.
039 */
040 public AuthenticatedAnnotationHandler() {
041 super(RequiresAuthentication.class);
042 }
043
044 /**
045 * Ensures that the calling <code>Subject</code> is authenticated, and if not, throws an
046 * {@link org.apache.shiro.authz.UnauthenticatedException UnauthenticatedException} indicating the method is not allowed to be executed.
047 *
048 * @param a the annotation to inspect
049 * @throws org.apache.shiro.authz.UnauthenticatedException if the calling <code>Subject</code> has not yet
050 * authenticated.
051 */
052 public void assertAuthorized(Annotation a) throws UnauthenticatedException {
053 if (a instanceof RequiresAuthentication && !getSubject().isAuthenticated() ) {
054 throw new UnauthenticatedException( "The current Subject is not authenticated. Access denied." );
055 }
056 }
057 }