VMware GemFire Java API Reference
Interface MethodInvocationAuthorizer
- All Known Implementing Classes:
ExampleAnnotationBasedMethodInvocationAuthorizer,JavaBeanAccessorMethodAuthorizer,RegExMethodAuthorizer,RestrictedMethodAuthorizer,UnrestrictedMethodAuthorizer
Method is
allowed to be executed on a specific Object instance. Implementations of this
interface should provide a no-arg constructor.
There are mainly four security risks when allowing users to execute arbitrary methods in OQL, which should be addressed by implementations of this interface:
Java Reflection: do anything throughObject.getClass()or similar.Cache Modification: executeCacheoperations (close, get regions, etc.).Region Modification: executeRegionoperations (destroy, invalidate, etc.).Region Entry Modification: execute in-place modifications on the region entries.
Implementations of this interface should be thread-safe: multiple threads might be authorizing several method invocations using the same instance at the same time.
-
Method Summary
Modifier and TypeMethodDescriptionbooleanExecutes the authorization logic to determine whether themethodis allowed to be executed on thetargetobject instance.default voidinitialize(Cache cache, Set<String> parameters)
-
Method Details
-
initialize
-
authorize
Executes the authorization logic to determine whether themethodis allowed to be executed on thetargetobject instance.Implementation Note: this method is called for every method invocation reached while traversing query results, for every target object seen, since the verdict may depend on the specific target instance (for example, per-
Regionaccess checks) and not solely on theMethodbeing invoked. The implementation should therefore be lightning fast, as it will be called by the OQL engine at runtime during query execution.
-