Class JexlPermissions.ClassPermissions
- All Implemented Interfaces:
JexlPermissions
- Enclosing interface:
JexlPermissions
A typical use case is to deny access to a package - and thus all its classes - but allow a few specific classes.
Note that the newer positive restriction syntax is preferable as in:
RESTRICTED.compose("java.lang { +Class {} }").
-
Nested Class Summary
Nested classes/interfaces inherited from interface org.apache.commons.jexl3.introspection.JexlPermissions
JexlPermissions.ClassPermissions, JexlPermissions.Delegate -
Field Summary
Fields inherited from class org.apache.commons.jexl3.introspection.JexlPermissions.Delegate
baseFields inherited from interface org.apache.commons.jexl3.introspection.JexlPermissions
RESTRICTED, UNRESTRICTED -
Constructor Summary
ConstructorsConstructorDescriptionClassPermissions(Class<?>... allow) Creates permissions based on the RESTRICTED set but allowing an explicit set.ClassPermissions(JexlPermissions permissions, Class<?>... allow) Creates permissions by augmenting an existing set with an explicit set of allowed classes.ClassPermissions(JexlPermissions delegate, Collection<String> allow) Creates permissions by augmenting an existing set with an explicit set of allowed canonical class names. -
Method Summary
Modifier and TypeMethodDescriptionbooleanChecks whether a class allows JEXL introspection.booleanChecks whether a field explicitly allows JEXL introspection.booleanChecks whether a method allows JEXL introspection.booleanallow(Constructor<?> constructor) Checks whether a constructor allows JEXL introspection.Compose these permissions with a new set.Methods inherited from class org.apache.commons.jexl3.introspection.JexlPermissions.Delegate
allow, allow, allow
-
Constructor Details
-
ClassPermissions
Creates permissions based on the RESTRICTED set but allowing an explicit set.- Parameters:
allow- the set of allowed classes
-
ClassPermissions
Creates permissions by augmenting an existing set with an explicit set of allowed classes.- Parameters:
permissions- the base permissions to augmentallow- the set of allowed classes
-
ClassPermissions
Creates permissions by augmenting an existing set with an explicit set of allowed canonical class names.- Parameters:
delegate- the base to delegate toallow- the list of class canonical names
-
-
Method Details
-
allow
Description copied from interface:JexlPermissionsChecks whether a constructor allows JEXL introspection.If a constructor is not allowed, the new operator cannot be used to instantiate its declared class in scripts or expressions.
- Specified by:
allowin interfaceJexlPermissions- Overrides:
allowin classJexlPermissions.Delegate- Parameters:
constructor- the constructor to check- Returns:
- true if JEXL is allowed to introspect, false otherwise
-
allow
Description copied from interface:JexlPermissionsChecks whether a class allows JEXL introspection.If the class disallows JEXL introspection, none of its constructors, methods or fields as well as derived classes are visible to JEXL and cannot be used in scripts or expressions. If one of its super-classes is not allowed, tbe class is not allowed either.
For interfaces, only methods and fields are disallowed in derived interfaces or implementing classes.
- Specified by:
allowin interfaceJexlPermissions- Overrides:
allowin classJexlPermissions.Delegate- Parameters:
clazz- the class to check- Returns:
- true if JEXL is allowed to introspect, false otherwise
-
allow
Description copied from interface:JexlPermissionsChecks whether a field explicitly allows JEXL introspection.If a field is not allowed, it cannot be resolved and accessed in scripts or expressions.
- Specified by:
allowin interfaceJexlPermissions- Overrides:
allowin classJexlPermissions.Delegate- Parameters:
clazz- the class from which the field is accessed, used to check that the field is allowed for this classfield- the field to check- Returns:
- true if JEXL is allowed to introspect, false otherwise
-
allow
Description copied from interface:JexlPermissionsChecks whether a method allows JEXL introspection.If a method is not allowed, it cannot be resolved and called in scripts or expressions.
Since methods can be overridden and overloaded, this checks that this class explicitly allows this method - superseding any superclass or interface specified permissions.
- Specified by:
allowin interfaceJexlPermissions- Overrides:
allowin classJexlPermissions.Delegate- Parameters:
clazz- the class from which the method is accessed, used to check that the method is allowed for this classmethod- the method to check- Returns:
- true if JEXL is allowed to introspect, false otherwise
-
compose
Description copied from interface:JexlPermissionsCompose these permissions with a new set.This is a convenience method meant to easily give access to the packages JEXL is used to integrate with. For instance, using
would extend the restricted set of permissions by allowing the com.my.app package.JexlPermissions.RESTRICTED.compose("com.my.app.*")- Specified by:
composein interfaceJexlPermissions- Overrides:
composein classJexlPermissions.Delegate- Parameters:
src- the new constraints- Returns:
- the new permissions
-