001/* 002 * Licensed to the Apache Software Foundation (ASF) under one 003 * or more contributor license agreements. See the NOTICE file 004 * distributed with this work for additional information 005 * regarding copyright ownership. The ASF licenses this file 006 * to you under the Apache License, Version 2.0 (the 007 * "License"); you may not use this file except in compliance 008 * with the License. You may obtain a copy of the License at 009 * 010 * http://www.apache.org/licenses/LICENSE-2.0 011 * 012 * Unless required by applicable law or agreed to in writing, 013 * software distributed under the License is distributed on an 014 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY 015 * KIND, either express or implied. See the License for the 016 * specific language governing permissions and limitations 017 * under the License. 018 */ 019package org.apache.shiro.authz.aop; 020 021import org.apache.shiro.authz.UnauthenticatedException; 022import org.apache.shiro.authz.UnauthorizedException; 023 024import javax.annotation.security.DenyAll; 025import java.lang.annotation.Annotation; 026 027/** 028 * This {@link org.apache.shiro.aop.AnnotationHandler AnnotationHandler} denys access from any subject 029 * (anonymous or logged in user). 030 * 031 * @since 2.0 032 */ 033public class DenyAllAnnotationHandler extends AuthorizingAnnotationHandler { 034 035 036 /** 037 * Default no-argument constructor that ensures this interceptor looks for 038 * <p> 039 * {@link org.apache.shiro.authz.annotation.RequiresGuest RequiresGuest} annotations in a method 040 * declaration. 041 */ 042 public DenyAllAnnotationHandler() { 043 super(DenyAll.class); 044 } 045 046 /** 047 * Causes a {@link UnauthorizedException} to be thrown if a DenyAll annotation is present. 048 * 049 * @param a the annotation to check for one or more roles 050 * @throws UnauthorizedException when the DenyAll annotation is present 051 */ 052 public void assertAuthorized(Annotation a) throws UnauthorizedException { 053 throw new UnauthenticatedException("Attempting to perform a denied operation."); 054 } 055}