public interface SecurityContext
An injectable interface that provides access to security related information.
- Since:
- 1.0
- Author:
- Paul Sandoz, Marc Hadley
- See Also:
- 
Field SummaryFieldsModifier and TypeFieldDescriptionstatic final StringString identifier for Basic authentication.static final StringString identifier for Client Certificate authentication.static final StringString identifier for Digest authentication.static final StringString identifier for Form authentication.
- 
Method SummaryModifier and TypeMethodDescriptionReturns the string value of the authentication scheme used to protect the resource.Returns ajava.security.Principalobject containing the name of the current authenticated user.booleanisSecure()Returns a boolean indicating whether this request was made using a secure channel, such as HTTPS.booleanisUserInRole(String role) Returns a boolean indicating whether the authenticated user is included in the specified logical "role".
- 
Field Details- 
BASIC_AUTHString identifier for Basic authentication. Value "BASIC"- See Also:
 
- 
CLIENT_CERT_AUTHString identifier for Client Certificate authentication. Value "CLIENT_CERT"- See Also:
 
- 
DIGEST_AUTHString identifier for Digest authentication. Value "DIGEST"- See Also:
 
- 
FORM_AUTHString identifier for Form authentication. Value "FORM"- See Also:
 
 
- 
- 
Method Details- 
getUserPrincipalPrincipal getUserPrincipal()Returns ajava.security.Principalobject containing the name of the current authenticated user. If the user has not been authenticated, the method returns null.- Returns:
- a java.security.Principalcontaining the name of the user making this request; null if the user has not been authenticated
- Throws:
- IllegalStateException- if called outside the scope of a request
 
- 
isUserInRoleReturns a boolean indicating whether the authenticated user is included in the specified logical "role". If the user has not been authenticated, the method returnsfalse.- Parameters:
- role- a- Stringspecifying the name of the role
- Returns:
- a booleanindicating whether the user making the request belongs to a given role;falseif the user has not been authenticated
- Throws:
- IllegalStateException- if called outside the scope of a request
 
- 
isSecureboolean isSecure()Returns a boolean indicating whether this request was made using a secure channel, such as HTTPS.- Returns:
- trueif the request was made using a secure channel,- falseotherwise
- Throws:
- IllegalStateException- if called outside the scope of a request
 
- 
getAuthenticationSchemeString getAuthenticationScheme()Returns the string value of the authentication scheme used to protect the resource. If the resource is not authenticated, null is returned. Values are the same as the CGI variable AUTH_TYPE- Returns:
- one of the static members BASIC_AUTH, FORM_AUTH, CLIENT_CERT_AUTH, DIGEST_AUTH (suitable for == comparison) or the container-specific string indicating the authentication scheme, or null if the request was not authenticated.
- Throws:
- IllegalStateException- if called outside the scope of a request
 
 
-