/usr/share/doc/libosgi-compendium-java/api/org/osgi/service/useradmin/Authorization.html is in libosgi-compendium-java-doc 5.0.0-5.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 | <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- NewPage -->
<html>
<head>
<!-- Generated by javadoc -->
<title>Authorization</title>
<link rel="stylesheet" type="text/css" href="../../../../stylesheet.css" title="Style">
<script type="text/javascript" src="../../../../script.js"></script>
</head>
<body>
<script type="text/javascript"><!--
try {
if (location.href.indexOf('is-external=true') == -1) {
parent.document.title="Authorization";
}
}
catch(err) {
}
//-->
var methods = {"i0":6,"i1":6,"i2":6};
var tabs = {65535:["t0","All Methods"],2:["t2","Instance Methods"],4:["t3","Abstract Methods"]};
var altColor = "altColor";
var rowColor = "rowColor";
var tableTab = "tableTab";
var activeTableTab = "activeTableTab";
</script>
<noscript>
<div>JavaScript is disabled on your browser.</div>
</noscript>
<!-- ========= START OF TOP NAVBAR ======= -->
<div class="topNav"><a name="navbar.top">
<!-- -->
</a>
<div class="skipNav"><a href="#skip.navbar.top" title="Skip navigation links">Skip navigation links</a></div>
<a name="navbar.top.firstrow">
<!-- -->
</a>
<ul class="navList" title="Navigation">
<li><a href="../../../../overview-summary.html">Overview</a></li>
<li><a href="package-summary.html">Package</a></li>
<li class="navBarCell1Rev">Class</li>
<li><a href="package-tree.html">Tree</a></li>
<li><a href="../../../../deprecated-list.html">Deprecated</a></li>
<li><a href="../../../../index-all.html">Index</a></li>
<li><a href="../../../../help-doc.html">Help</a></li>
</ul>
</div>
<div class="subNav">
<ul class="navList">
<li>Prev Class</li>
<li><a href="../../../../org/osgi/service/useradmin/Group.html" title="interface in org.osgi.service.useradmin"><span class="typeNameLink">Next Class</span></a></li>
</ul>
<ul class="navList">
<li><a href="../../../../index.html?org/osgi/service/useradmin/Authorization.html" target="_top">Frames</a></li>
<li><a href="Authorization.html" target="_top">No Frames</a></li>
</ul>
<ul class="navList" id="allclasses_navbar_top">
<li><a href="../../../../allclasses-noframe.html">All Classes</a></li>
</ul>
<div>
<script type="text/javascript"><!--
allClassesLink = document.getElementById("allclasses_navbar_top");
if(window==top) {
allClassesLink.style.display = "block";
}
else {
allClassesLink.style.display = "none";
}
//-->
</script>
</div>
<div>
<ul class="subNavList">
<li>Summary: </li>
<li>Nested | </li>
<li>Field | </li>
<li>Constr | </li>
<li><a href="#method.summary">Method</a></li>
</ul>
<ul class="subNavList">
<li>Detail: </li>
<li>Field | </li>
<li>Constr | </li>
<li><a href="#method.detail">Method</a></li>
</ul>
</div>
<a name="skip.navbar.top">
<!-- -->
</a></div>
<!-- ========= END OF TOP NAVBAR ========= -->
<!-- ======== START OF CLASS DATA ======== -->
<div class="header">
<div class="subTitle">org.osgi.service.useradmin</div>
<h2 title="Interface Authorization" class="title">Interface Authorization</h2>
</div>
<div class="contentContainer">
<div class="description">
<ul class="blockList">
<li class="blockList">
<hr>
<br>
<pre>public interface <span class="typeNameLabel">Authorization</span></pre>
<div class="block">The <code>Authorization</code> interface encapsulates an authorization context on
which bundles can base authorization decisions, where appropriate.
<p>
Bundles associate the privilege to access restricted resources or operations
with roles. Before granting access to a restricted resource or operation, a
bundle will check if the <code>Authorization</code> object passed to it possess
the required role, by calling its <code>hasRole</code> method.
<p>
Authorization contexts are instantiated by calling the
<a href="../../../../org/osgi/service/useradmin/UserAdmin.html#getAuthorization-org.osgi.service.useradmin.User-"><code>UserAdmin.getAuthorization(User)</code></a> method.
<p>
<i>Trusting Authorization objects </i>
<p>
There are no restrictions regarding the creation of <code>Authorization</code>
objects. Hence, a service must only accept <code>Authorization</code> objects from
bundles that has been authorized to use the service using code based (or Java
2) permissions.
<p>
In some cases it is useful to use <code>ServicePermission</code> to do the code
based access control. A service basing user access control on
<code>Authorization</code> objects passed to it, will then require that a calling
bundle has the <code>ServicePermission</code> to get the service in question. This
is the most convenient way. The OSGi environment will do the code based
permission check when the calling bundle attempts to get the service from the
service registry.
<p>
Example: A servlet using a service on a user's behalf. The bundle with the
servlet must be given the <code>ServicePermission</code> to get the Http Service.
<p>
However, in some cases the code based permission checks need to be more
fine-grained. A service might allow all bundles to get it, but require
certain code based permissions for some of its methods.
<p>
Example: A servlet using a service on a user's behalf, where some service
functionality is open to anyone, and some is restricted by code based
permissions. When a restricted method is called (e.g., one handing over an
<code>Authorization</code> object), the service explicitly checks that the calling
bundle has permission to make the call.</div>
</li>
</ul>
</div>
<div class="summary">
<ul class="blockList">
<li class="blockList">
<!-- ========== METHOD SUMMARY =========== -->
<ul class="blockList">
<li class="blockList"><a name="method.summary">
<!-- -->
</a>
<h3>Method Summary</h3>
<table class="memberSummary" border="0" cellpadding="3" cellspacing="0" summary="Method Summary table, listing methods, and an explanation">
<caption><span id="t0" class="activeTableTab"><span>All Methods</span><span class="tabEnd"> </span></span><span id="t2" class="tableTab"><span><a href="javascript:show(2);">Instance Methods</a></span><span class="tabEnd"> </span></span><span id="t3" class="tableTab"><span><a href="javascript:show(4);">Abstract Methods</a></span><span class="tabEnd"> </span></span></caption>
<tr>
<th class="colFirst" scope="col">Modifier and Type</th>
<th class="colLast" scope="col">Method and Description</th>
</tr>
<tr id="i0" class="altColor">
<td class="colFirst"><code>java.lang.String</code></td>
<td class="colLast"><code><span class="memberNameLink"><a href="../../../../org/osgi/service/useradmin/Authorization.html#getName--">getName</a></span>()</code>
<div class="block">Gets the name of the <a href="../../../../org/osgi/service/useradmin/User.html" title="interface in org.osgi.service.useradmin"><code>User</code></a> that this <code>Authorization</code> context
was created for.</div>
</td>
</tr>
<tr id="i1" class="rowColor">
<td class="colFirst"><code>java.lang.String[]</code></td>
<td class="colLast"><code><span class="memberNameLink"><a href="../../../../org/osgi/service/useradmin/Authorization.html#getRoles--">getRoles</a></span>()</code>
<div class="block">Gets the names of all roles implied by this <code>Authorization</code>
context.</div>
</td>
</tr>
<tr id="i2" class="altColor">
<td class="colFirst"><code>boolean</code></td>
<td class="colLast"><code><span class="memberNameLink"><a href="../../../../org/osgi/service/useradmin/Authorization.html#hasRole-java.lang.String-">hasRole</a></span>(java.lang.String name)</code>
<div class="block">Checks if the role with the specified name is implied by this
<code>Authorization</code> context.</div>
</td>
</tr>
</table>
</li>
</ul>
</li>
</ul>
</div>
<div class="details">
<ul class="blockList">
<li class="blockList">
<!-- ============ METHOD DETAIL ========== -->
<ul class="blockList">
<li class="blockList"><a name="method.detail">
<!-- -->
</a>
<h3>Method Detail</h3>
<a name="getName--">
<!-- -->
</a>
<ul class="blockList">
<li class="blockList">
<h4>getName</h4>
<pre>java.lang.String getName()</pre>
<div class="block">Gets the name of the <a href="../../../../org/osgi/service/useradmin/User.html" title="interface in org.osgi.service.useradmin"><code>User</code></a> that this <code>Authorization</code> context
was created for.</div>
<dl>
<dt><span class="returnLabel">Returns:</span></dt>
<dd>The name of the <a href="../../../../org/osgi/service/useradmin/User.html" title="interface in org.osgi.service.useradmin"><code>User</code></a> object that this
<code>Authorization</code> context was created for, or <code>null</code> if
no user was specified when this <code>Authorization</code> context was
created.</dd>
</dl>
</li>
</ul>
<a name="hasRole-java.lang.String-">
<!-- -->
</a>
<ul class="blockList">
<li class="blockList">
<h4>hasRole</h4>
<pre>boolean hasRole(java.lang.String name)</pre>
<div class="block">Checks if the role with the specified name is implied by this
<code>Authorization</code> context.
<p>
Bundles must define globally unique role names that are associated with
the privilege of accessing restricted resources or operations. Operators
will grant users access to these resources, by creating a <a href="../../../../org/osgi/service/useradmin/Group.html" title="interface in org.osgi.service.useradmin"><code>Group</code></a>
object for each role and adding <a href="../../../../org/osgi/service/useradmin/User.html" title="interface in org.osgi.service.useradmin"><code>User</code></a> objects to it.</div>
<dl>
<dt><span class="paramLabel">Parameters:</span></dt>
<dd><code>name</code> - The name of the role to check for.</dd>
<dt><span class="returnLabel">Returns:</span></dt>
<dd><code>true</code> if this <code>Authorization</code> context implies the
specified role, otherwise <code>false</code>.</dd>
</dl>
</li>
</ul>
<a name="getRoles--">
<!-- -->
</a>
<ul class="blockListLast">
<li class="blockList">
<h4>getRoles</h4>
<pre>java.lang.String[] getRoles()</pre>
<div class="block">Gets the names of all roles implied by this <code>Authorization</code>
context.</div>
<dl>
<dt><span class="returnLabel">Returns:</span></dt>
<dd>The names of all roles implied by this <code>Authorization</code>
context, or <code>null</code> if no roles are in the context. The
predefined role <code>user.anyone</code> will not be included in this
list.</dd>
</dl>
</li>
</ul>
</li>
</ul>
</li>
</ul>
</div>
</div>
<!-- ========= END OF CLASS DATA ========= -->
<!-- ======= START OF BOTTOM NAVBAR ====== -->
<div class="bottomNav"><a name="navbar.bottom">
<!-- -->
</a>
<div class="skipNav"><a href="#skip.navbar.bottom" title="Skip navigation links">Skip navigation links</a></div>
<a name="navbar.bottom.firstrow">
<!-- -->
</a>
<ul class="navList" title="Navigation">
<li><a href="../../../../overview-summary.html">Overview</a></li>
<li><a href="package-summary.html">Package</a></li>
<li class="navBarCell1Rev">Class</li>
<li><a href="package-tree.html">Tree</a></li>
<li><a href="../../../../deprecated-list.html">Deprecated</a></li>
<li><a href="../../../../index-all.html">Index</a></li>
<li><a href="../../../../help-doc.html">Help</a></li>
</ul>
</div>
<div class="subNav">
<ul class="navList">
<li>Prev Class</li>
<li><a href="../../../../org/osgi/service/useradmin/Group.html" title="interface in org.osgi.service.useradmin"><span class="typeNameLink">Next Class</span></a></li>
</ul>
<ul class="navList">
<li><a href="../../../../index.html?org/osgi/service/useradmin/Authorization.html" target="_top">Frames</a></li>
<li><a href="Authorization.html" target="_top">No Frames</a></li>
</ul>
<ul class="navList" id="allclasses_navbar_bottom">
<li><a href="../../../../allclasses-noframe.html">All Classes</a></li>
</ul>
<div>
<script type="text/javascript"><!--
allClassesLink = document.getElementById("allclasses_navbar_bottom");
if(window==top) {
allClassesLink.style.display = "block";
}
else {
allClassesLink.style.display = "none";
}
//-->
</script>
</div>
<div>
<ul class="subNavList">
<li>Summary: </li>
<li>Nested | </li>
<li>Field | </li>
<li>Constr | </li>
<li><a href="#method.summary">Method</a></li>
</ul>
<ul class="subNavList">
<li>Detail: </li>
<li>Field | </li>
<li>Constr | </li>
<li><a href="#method.detail">Method</a></li>
</ul>
</div>
<a name="skip.navbar.bottom">
<!-- -->
</a></div>
<!-- ======== END OF BOTTOM NAVBAR ======= -->
</body>
</html>
|