Deprecated
for removal since 17.
This class is only useful in conjunction with the Security Manager, which is deprecated and subject to removal in a future release. Consequently, this class is also deprecated and subject to removal. There is no replacement for the Security Manager or this class.
The AccessController
class is used for access control operations
and decisions.
More specifically, the AccessController
class is used for
three purposes:
The checkPermission
method
determines whether the access request indicated by a specified
permission should be granted or denied. A sample call appears
below. In this example, checkPermission
will determine
whether or not to grant "read" access to the file named "testFile" in
the "/temp" directory.
FilePermission perm = new FilePermission("/temp/testFile", "read"); AccessController.checkPermission(perm);
If a requested access is allowed,
checkPermission
returns quietly. If denied, an
AccessControlException
is
thrown. AccessControlException
can also be thrown if the requested
permission is of an incorrect type or contains an invalid value.
Such information is given whenever possible.
Suppose the current thread traversed m callers, in the order of caller 1
to caller 2 to caller m. Then caller m invoked the
checkPermission
method.
The checkPermission
method determines whether access
is granted or denied based on the following algorithm:
for (int i = m; i > 0; i--) {
if (caller i's domain does not have the permission)
throw AccessControlException
else if (caller i is marked as privileged) {
if (a context was specified in the call to doPrivileged)
context.checkPermission(permission)
if (limited permissions were specified in the call to doPrivileged) {
for (each limited permission) {
if (the limited permission implies the requested permission)
return;
}
} else
return;
}
}
// Next, check the context inherited when the thread was created.
// Whenever a new thread is created, the AccessControlContext at
// that time is stored and associated with the new thread, as the
// "inherited" context.
inheritedContext.checkPermission(permission);
A caller can be marked as being "privileged"
(see doPrivileged
and below).
When making access control decisions, the checkPermission
method stops checking if it reaches a caller that
was marked as "privileged" via a doPrivileged
call without a context argument (see below for information about a
context argument). If that caller's domain has the
specified permission and at least one limiting permission argument (if any)
implies the requested permission, no further checking is done and
checkPermission
returns quietly, indicating that the requested access is allowed.
If that domain does not have the specified permission, an exception
is thrown, as usual. If the caller's domain had the specified permission
but it was not implied by any limiting permission arguments given in the call
to doPrivileged
then the permission checking continues
until there are no more callers or another doPrivileged
call matches the requested permission and returns normally.
The normal use of the "privileged" feature is as follows. If you don't need to return a value from within the "privileged" block, do the following:
somemethod() {
...normal code here...
AccessController.doPrivileged(new PrivilegedAction<Void>() {
public Void run() {
// privileged code goes here, for example:
System.loadLibrary("awt");
return null; // nothing to return
}
});
...normal code here...
}
PrivilegedAction
is an interface with a single method, named
run
.
The above example shows creation of an implementation
of that interface; a concrete implementation of the
run
method is supplied.
When the call to doPrivileged
is made, an
instance of the PrivilegedAction
implementation is passed
to it. The doPrivileged
method calls the
run
method from the PrivilegedAction
implementation after enabling privileges, and returns the
run
method's return value as the
doPrivileged
return value (which is
ignored in this example).
If you need to return a value, you can do something like the following:
somemethod() {
...normal code here...
String user = AccessController.doPrivileged(
new PrivilegedAction<String>() {
public String run() {
return System.getProperty("user.name");
}
});
...normal code here...
}
If the action performed in your run
method could
throw a "checked" exception (those listed in the throws
clause
of a method), then you need to use the
PrivilegedExceptionAction
interface instead of the
PrivilegedAction
interface:
somemethod() throws FileNotFoundException {
...normal code here...
try {
FileInputStream fis = AccessController.doPrivileged(
new PrivilegedExceptionAction<FileInputStream>() {
public FileInputStream run() throws FileNotFoundException {
return new FileInputStream("someFile");
}
});
} catch (PrivilegedActionException e) {
// e.getException() should be an instance of FileNotFoundException,
// as only "checked" exceptions will be "wrapped" in a
// PrivilegedActionException.
throw (FileNotFoundException) e.getException();
}
...normal code here...
}
Be *very* careful in your use of the "privileged" construct, and
always remember to make the privileged code section as small as possible.
You can pass Permission
arguments to further limit the
scope of the "privilege" (see below).
Note that checkPermission
always performs security checks
within the context of the currently executing thread.
Sometimes a security check that should be made within a given context
will actually need to be done from within a
different context (for example, from within a worker thread).
The getContext
method and
AccessControlContext
class are provided
for this situation. The getContext
method takes a "snapshot"
of the current calling context, and places
it in an AccessControlContext
object, which it returns. A sample call is
the following:
AccessControlContext acc = AccessController.getContext()
AccessControlContext
itself has a checkPermission
method
that makes access decisions based on the context it encapsulates,
rather than that of the current execution thread.
Code within a different context can thus call that method on the
previously-saved AccessControlContext
object. A sample call is the
following:
acc.checkPermission(permission)
There are also times where you don't know a priori which permissions
to check the context against. In these cases you can use the
doPrivileged
method that takes a context. You can also limit the
scope of the privileged code by passing additional Permission
parameters.
somemethod() {
AccessController.doPrivileged(new PrivilegedAction<Object>() {
public Object run() {
// Code goes here. Any permission checks within this
// run method will require that the intersection of the
// caller's protection domain and the snapshot's
// context have the desired permission. If a requested
// permission is not implied by the limiting FilePermission
// argument then checking of the thread continues beyond the
// caller of doPrivileged.
}
}, acc, new FilePermission("/temp/*", read));
...normal code here...
}
Passing a limiting Permission
argument of an instance of
AllPermission
is equivalent to calling the equivalent
doPrivileged
method without limiting Permission
arguments. Passing a zero length array of Permission
disables
the code privileges so that checking always continues beyond the caller of
that doPrivileged
method.
AccessControlContext
Modifier and Type | Class and Description |
---|---|
private static class |
Access | Constructor and Description |
---|---|
private |
Modifier and Type | Method and Description |
---|---|
private static AccessControlContext | checkContext(AccessControlContext context, Class<?> caller)
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
|
public static void | checkPermission(Permission
the requested permission. perm)Determines whether the access request indicated by the
specified permission should be allowed or denied, based on
the current |
private static AccessControlContext | createWrapper(DomainCombiner combiner, Class<?> caller, AccessControlContext parent, AccessControlContext context, Permission[] perms)
References Deprecated
DomainCombiner and AccessControlContext are deprecated or reference (maybe indirectly) at least one deprecated element.
Create a wrapper to contain the limited privilege scope data. |
public static < the type of the value returned by the PrivilegedAction's
T> Trun method. | Returns: the value returned by the action'srun method.the action to be performed. action)Performs the specified |
public static < the type of the value returned by the PrivilegedAction's
T> Trun method. | Returns: the value returned by the action'srun method.the action to be performed. action, AccessControlContext an access control context
representing the restriction to be applied to the
caller's domain's privileges before performing
the specified action. If the context is
context)null , then no additional restriction is applied.
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
Performs the specified |
public static < the type of the value returned by the PrivilegedAction's
T> Trun method. | Returns: the value returned by the action'srun method.the action to be performed. action, AccessControlContext an access control context
representing the restriction to be applied to the
caller's domain's privileges before performing
the specified action. If the context is
context, Permission... null ,
then no additional restriction is applied.the perms)Permission arguments which limit the
scope of the caller's privileges. The number of arguments
is variable.
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
Performs the specified |
public static < the type of the value returned by the
PrivilegedExceptionAction's T> Trun method. | Returns: the value returned by the action'srun methodthe action to be performed action)Performs the specified |
public static < the type of the value returned by the
PrivilegedExceptionAction's T> Trun method. | Returns: the value returned by the action'srun methodthe action to be performed action, AccessControlContext an access control context
representing the restriction to be applied to the
caller's domain's privileges before performing
the specified action. If the context is
context)null , then no additional restriction is applied.
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
Performs the specified |
public static < the type of the value returned by the
PrivilegedExceptionAction's T> Trun method. | Returns: the value returned by the action'srun method.the action to be performed. action, AccessControlContext an access control context
representing the restriction to be applied to the
caller's domain's privileges before performing
the specified action. If the context is
context, Permission... null ,
then no additional restriction is applied.the perms)Permission arguments which limit the
scope of the caller's privileges. The number of arguments
is variable.
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
Performs the specified |
public static < the type of the value returned by the PrivilegedAction's
T> Trun method. | Returns: the value returned by the action'srun method.the action to be performed. action)Performs the specified |
public static < the type of the value returned by the PrivilegedAction's
T> Trun method. | Returns: the value returned by the action'srun method.the action to be performed. action, AccessControlContext an access control context
representing the restriction to be applied to the
caller's domain's privileges before performing
the specified action. If the context is
context, Permission... null ,
then no additional restriction is applied.the perms)Permission arguments which limit the
scope of the caller's privileges. The number of arguments
is variable.
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
Performs the specified |
public static < the type of the value returned by the
PrivilegedExceptionAction's T> Trun method. | Returns: the value returned by the action'srun methodthe action to be performed. action)Performs the specified |
public static < the type of the value returned by the
PrivilegedExceptionAction's T> Trun method. | Returns: the value returned by the action'srun method.the action to be performed. action, AccessControlContext an access control context
representing the restriction to be applied to the
caller's domain's privileges before performing
the specified action. If the context is
context, Permission... null ,
then no additional restriction is applied.the perms)Permission arguments which limit the
scope of the caller's privileges. The number of arguments
is variable.
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
Performs the specified |
private static native void | ensureMaterializedForStackWalk(Object o)
The value needs to be physically located in the frame, so that it can be found by a stack walk. |
private static <T> T | executePrivileged(PrivilegedAction<T> action, AccessControlContext context, Class<?> caller)
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
Execute the action as privileged. |
private static <T> T | executePrivileged(PrivilegedExceptionAction<T> action, AccessControlContext context, Class<?> caller)
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
Execute the action as privileged. |
public static AccessControlContext | Returns: theAccessControlContext based on the current context.
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
This method takes a "snapshot" of the current calling context, which
includes the current thread's inherited |
pack-priv static native AccessControlContext | getInheritedAccessControlContext()
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
Returns the "inherited" |
private static AccessControlContext | getInnocuousAcc()
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
|
private static native ProtectionDomain | |
private static native AccessControlContext | Returns: the access control context based on the current stack ornull if there was only privileged system code.
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
Returns the |
private static boolean | |
private static AccessControlContext | preserveCombiner(DomainCombiner combiner, Class<?> caller)
References Deprecated
DomainCombiner and AccessControlContext are deprecated or reference (maybe indirectly) at least one deprecated element.
preserve the combiner across the doPrivileged call |
private static PrivilegedActionException |
AccessController | back to summary |
---|---|
private AccessController() Don't allow anyone to instantiate an |
checkContext | back to summary |
---|---|
private static AccessControlContext checkContext(AccessControlContext context, Class<?> caller)
References Deprecated
See corresponding docs for further information.
|
checkPermission | back to summary |
---|---|
public static void checkPermission(Permission perm) throws AccessControlException Determines whether the access request indicated by the
specified permission should be allowed or denied, based on
the current
|
createWrapper | back to summary |
---|---|
private static AccessControlContext createWrapper(DomainCombiner combiner, Class<?> caller, AccessControlContext parent, AccessControlContext context, Permission[] perms)
References Deprecated
See corresponding docs for further information. Create a wrapper to contain the limited privilege scope data.
|
doPrivileged | back to summary |
---|---|
public static <T> T doPrivileged(PrivilegedAction<T> action) Performs the specified If the action's Note that any
|
doPrivileged | back to summary |
---|---|
public static <T> T doPrivileged(PrivilegedAction<T> action, AccessControlContext context)
References Deprecated
See corresponding docs for further information. Performs the specified
If the action's
If a security manager is installed and the specified
|
doPrivileged | back to summary |
---|---|
public static <T> T doPrivileged(PrivilegedAction<T> action, AccessControlContext context, Permission... perms)
References Deprecated
See corresponding docs for further information. Performs the specified
If the action's
If a security manager is installed and the specified
|
doPrivileged | back to summary |
---|---|
public static <T> T doPrivileged(PrivilegedExceptionAction<T> action) throws PrivilegedActionException Performs the specified If the action's Note that any
|
doPrivileged | back to summary |
---|---|
public static <T> T doPrivileged(PrivilegedExceptionAction<T> action, AccessControlContext context) throws PrivilegedActionException
References Deprecated
See corresponding docs for further information. Performs the specified
If the action's
If a security manager is installed and the specified
|
doPrivileged | back to summary |
---|---|
public static <T> T doPrivileged(PrivilegedExceptionAction<T> action, AccessControlContext context, Permission... perms) throws PrivilegedActionException
References Deprecated
See corresponding docs for further information. Performs the specified
If the action's
If a security manager is installed and the specified
|
doPrivilegedWithCombiner | back to summary |
---|---|
public static <T> T doPrivilegedWithCombiner(PrivilegedAction<T> action) Performs the specified If the action's This method preserves the current AccessControlContext's
|
doPrivilegedWithCombiner | back to summary |
---|---|
public static <T> T doPrivilegedWithCombiner(PrivilegedAction<T> action, AccessControlContext context, Permission... perms)
References Deprecated
See corresponding docs for further information. Performs the specified
If the action's This method preserves the current AccessControlContext's
If a security manager is installed and the specified
|
doPrivilegedWithCombiner | back to summary |
---|---|
public static <T> T doPrivilegedWithCombiner(PrivilegedExceptionAction<T> action) throws PrivilegedActionException Performs the specified If the action's This method preserves the current AccessControlContext's
|
doPrivilegedWithCombiner | back to summary |
---|---|
public static <T> T doPrivilegedWithCombiner(PrivilegedExceptionAction<T> action, AccessControlContext context, Permission... perms) throws PrivilegedActionException
References Deprecated
See corresponding docs for further information. Performs the specified
If the action's This method preserves the current AccessControlContext's
If a security manager is installed and the specified
|
ensureMaterializedForStackWalk | back to summary |
---|---|
private static native void ensureMaterializedForStackWalk(Object o) The value needs to be physically located in the frame, so that it can be found by a stack walk.
|
executePrivileged | back to summary |
---|---|
private static <T> T executePrivileged(PrivilegedAction<T> action, AccessControlContext context, Class<?> caller)
References Deprecated
See corresponding docs for further information. Execute the action as privileged. The VM recognizes this method as special, so any changes to the name or signature require corresponding changes in getStackAccessControlContext().
|
executePrivileged | back to summary |
---|---|
private static <T> T executePrivileged(PrivilegedExceptionAction<T> action, AccessControlContext context, Class<?> caller) throws Exception
References Deprecated
See corresponding docs for further information. Execute the action as privileged. The VM recognizes this method as special, so any changes to the name or signature require corresponding changes in getStackAccessControlContext().
|
getContext | back to summary |
---|---|
public static AccessControlContext getContext()
References Deprecated
See corresponding docs for further information. This method takes a "snapshot" of the current calling context, which
includes the current thread's inherited
|
getInheritedAccessControlContext | back to summary |
---|---|
pack-priv static native AccessControlContext getInheritedAccessControlContext()
References Deprecated
See corresponding docs for further information. Returns the "inherited"
|
getInnocuousAcc | back to summary |
---|---|
private static AccessControlContext getInnocuousAcc()
References Deprecated
See corresponding docs for further information.
|
getProtectionDomain | back to summary |
---|---|
private static native ProtectionDomain getProtectionDomain(final Class<?> caller) |
getStackAccessControlContext | back to summary |
---|---|
private static native AccessControlContext getStackAccessControlContext()
References Deprecated
See corresponding docs for further information. Returns the
|
isPrivileged | back to summary |
---|---|
private static boolean isPrivileged() Sanity check that the caller context is indeed privileged.
Used by |
preserveCombiner | back to summary |
---|---|
private static AccessControlContext preserveCombiner(DomainCombiner combiner, Class<?> caller)
References Deprecated
See corresponding docs for further information. preserve the combiner across the doPrivileged call
|
wrapException | back to summary |
---|---|
private static PrivilegedActionException wrapException(Exception e) Wrap an exception. The annotations are used in a best effort to avoid StackOverflowError in the caller. Inlining the callees as well and tail-call elimination could also help here, but are not needed for correctness, only quality of implementation.
|
Modifier and Type | Field and Description |
---|---|
pack-priv static final AccessControlContext | innocuousAcc
References Deprecated
AccessControlContext is deprecated or references (maybe indirectly) at least one deprecated element.
|
Access | Constructor and Description |
---|---|
private |
innocuousAcc | back to summary |
---|---|
pack-priv static final AccessControlContext innocuousAcc
References Deprecated
See corresponding docs for further information.
|
AccHolder | back to summary |
---|---|
private AccHolder() |