Some changes to security implementation
Set default evaluation result to false and throw an AccessDeniedException. SecurityExceptionControllerAdvice checks if there is an valid login and decides whether to send HTTP 401 or HTTP 403. Conflicts: src/test/java/de/thm/arsnova/controller/AbstractControllerTest.java
Showing
- src/main/java/de/thm/arsnova/controller/SecurityExceptionControllerAdvice.java 19 additions, 7 deletions...arsnova/controller/SecurityExceptionControllerAdvice.java
- src/main/java/de/thm/arsnova/security/ApplicationPermissionEvaluator.java 12 additions, 11 deletions.../thm/arsnova/security/ApplicationPermissionEvaluator.java
- src/test/java/de/thm/arsnova/controller/AbstractControllerTest.java 39 additions, 0 deletions...ava/de/thm/arsnova/controller/AbstractControllerTest.java
- src/test/java/de/thm/arsnova/controller/SessionControllerTest.java 18 additions, 0 deletions...java/de/thm/arsnova/controller/SessionControllerTest.java
- src/test/java/de/thm/arsnova/services/QuestionServiceTest.java 4 additions, 4 deletions...est/java/de/thm/arsnova/services/QuestionServiceTest.java
- src/test/java/de/thm/arsnova/services/SessionServiceTest.java 3 additions, 3 deletions...test/java/de/thm/arsnova/services/SessionServiceTest.java
Please register or sign in to comment