Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-4288

SecureAnnotationsInterceptor maps roles only based on method name

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.3.10, 2.4.7, 2.5.3, 2.6
    • 2.3.11, 2.4.8, 2.5.4, 2.6.1
    • Core
    • None
    • Unknown

    Description

      The SecureAnnotationsInterceptor maps the roles into the method map only based on the method name. If the class in question is using overloaded methods with different roles for each method, this can result in the wrong roles being applied to the authorization. The map needs to take into account the params/returns as well.

      Attachments

        Activity

          People

            dkulp Daniel Kulp
            dkulp Daniel Kulp
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: