01: /*
02: * $Id: AuthorizeAction.java 471754 2006-11-06 14:55:09Z husted $
03: *
04: * Licensed to the Apache Software Foundation (ASF) under one
05: * or more contributor license agreements. See the NOTICE file
06: * distributed with this work for additional information
07: * regarding copyright ownership. The ASF licenses this file
08: * to you under the Apache License, Version 2.0 (the
09: * "License"); you may not use this file except in compliance
10: * with the License. You may obtain a copy of the License at
11: *
12: * http://www.apache.org/licenses/LICENSE-2.0
13: *
14: * Unless required by applicable law or agreed to in writing,
15: * software distributed under the License is distributed on an
16: * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
17: * KIND, either express or implied. See the License for the
18: * specific language governing permissions and limitations
19: * under the License.
20: */
21: package org.apache.struts.chain.commands.servlet;
22:
23: import org.apache.struts.action.ActionServlet;
24: import org.apache.struts.chain.commands.AbstractAuthorizeAction;
25: import org.apache.struts.chain.contexts.ActionContext;
26: import org.apache.struts.chain.contexts.ServletActionContext;
27: import org.apache.struts.config.ActionConfig;
28: import org.apache.struts.util.MessageResources;
29:
30: import javax.servlet.http.HttpServletRequest;
31:
32: /**
33: * <p>Determine if the action is authorized for the given roles.</p>
34: *
35: * @version $Rev: 471754 $ $Date: 2005-11-12 13:01:44 -0500 (Sat, 12 Nov 2005)
36: * $
37: */
38: public class AuthorizeAction extends AbstractAuthorizeAction {
39: // ------------------------------------------------------- Protected Methods
40: protected boolean isAuthorized(ActionContext context,
41: String[] roles, ActionConfig mapping) throws Exception {
42: // Identify the HTTP request object
43: ServletActionContext servletActionContext = (ServletActionContext) context;
44: HttpServletRequest request = servletActionContext.getRequest();
45:
46: // Check the current user against the list of required roles
47: for (int i = 0; i < roles.length; i++) {
48: if (request.isUserInRole(roles[i])) {
49: return (true);
50: }
51: }
52:
53: // Default to unauthorized
54: return (false);
55: }
56:
57: protected String getErrorMessage(ActionContext context,
58: ActionConfig actionConfig) {
59: ServletActionContext servletActionContext = (ServletActionContext) context;
60:
61: // Retrieve internal message resources
62: ActionServlet servlet = servletActionContext.getActionServlet();
63: MessageResources resources = servlet.getInternal();
64:
65: return resources.getMessage("notAuthorized", actionConfig
66: .getPath());
67: }
68: }
|