KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
servletApi() support of Spring Security is great. I want to inject custom Principal as this: public interface UserPrincipal extends Principal { public Integer getId(); } @RequestMapping(value = "/") public ResponseEntity<List<Conversation>> listAfter(UserPrincipal user){ // implementation } or @RequestMapping(value = "/") public ResponseEntity<List<Conversation>> listAfter(UserPrincipalImpl user){ // implementation } Spring has support for injecting Principal instances with the help of ServletRequestMethodArgumentResolver . It is injecting principal as this: else if (Principal.class.isAssignableFrom(paramType)) { return request.getUserPrincipal(); } Here is the place where the problem begins. request is here an instance of SecurityContextHolderAwareRequestWrapper . It has an implementation of: @Override public Principal getUserPrincipal() { Authentication auth = getAuthentication(); if ((auth == null) || (auth.getPrincipal() == null)) { return null; } return auth; } Because an Authentication is also an Principal . (The only part of spring security I did not like so far. I will ask this a separate question as well.) This is causing a problem. Because Authentication is a Principal not a UserPrincipal . How can I resolve this problem? Do I need to implement an authentication which is a UserPrincipal as well? Or should I change HandlerMethodArgumentResolver order a create a custom resolver? (This is not easy for Spring MVC because internal handlers has higher priority.) As a extra information: I am using Spring Security M2 and my configuration for AuthenticationManagerBuilder is simply: @Override protected vo
Tags (comma-separated)
Save Edits
Cancel