创建Restlet Authorizer以进行细粒度授权

时间:2013-05-11 16:13:26

标签: java api rest restlet restlet-2.0

我尝试使用Restlet实现RESTful API,并且除了基本的角色和方法授权器之外,我发现的内容很少。我已经在数据库中存储了用户可以访问的路由的路由和方法。我现在遇到的问题是如何在Authorizer中获取路径。这是我需要收集的资源吗?我应该如何路由到授权人?到目前为止,我已经发布了我的版权所有者,以了解如何获取路径或资源。任何信息都值得赞赏,我看过书籍和许多通用的例子,并且找不到我正在寻找的东西。

我的路由应用程序:

public class MyRoutingApp extends org.restlet.Application {

    @Override  
    public synchronized Restlet createInboundRoot() { 

        Context context = getContext();
        Router router = new Router(context);

        router.attach("/user", Users.class);
        router.attach("/post", Posts.class);
        router.attach("/comment", Comments.class);

        ChallengeAuthenticator authenticator = new ChallengeAuthenticator( 
                context, ChallengeScheme.HTTP_BASIC, "My test realm" );

        //create Verifier to ensure that the user is authenicated
        MyVerifier verifier = new MySecretVerifier();
        //grab user Roles and add them to the request
        MyEnroler enroler = new MyEnroler();

        authenticator.setVerifier( verifier );
        authenticator.setEnroler( enroler );

        //Looks up if user can be allowed to resource
        MyAuthorizer authorizer = new MyAuthorizer();
        authorizer.setNext( router );

        authenticator.setNext( authorizer );
        return authenticator; 
    }
}

我的授权人:

public class MyAuthorizer extends Authorizer {

    @Override
    protected boolean authorize( Request request, Response response ) {

        //has the security roles and user from verifier and enroler
        ClientInfo info = request.getClientInfo();
        //get http method
        Method method = request.getMethod();

        //need to get the route or resource user is attempting to access
        //allow or disallow access based on roles and method
    }
}

1 个答案:

答案 0 :(得分:2)

目标资源URI可通过Request#getResouceRef()。getRemainingPart()获得。