Annotation Interface AccessDeniedErrorRouter
AnnotatedViewAccessChecker. Annotation is to be used together with
@Route, or if present, together with access annotation listed here:
@AnonymousAllowed@PermitAll@RolesAllowed@DenyAll
@AccessDeniedErrorRouter(rerouteToError = CustomAccessDeniedException.class)
@RolesAllowed("admin")
@Route("test")
public class TestView extends Div {
}
@AccessDeniedErrorRouter(rerouteToError = CustomAccessDeniedException.class)
@RolesAllowed("admin")
public class ParentView extends Div {
}
@Route("subview")
public class SubView extends ParentView {
}
public class CustomAccessDeniedException extends RuntimeException {
public CustomAccessDeniedException() {
}
public CustomAccessDeniedException(String message) {
super(message);
}
}
@Tag(Tag.DIV)
public class CustomAccessDeniedError
implements HasErrorParameter<CustomAccessDeniedException> {
@Override
public int setErrorParameter(BeforeEnterEvent event,
ErrorParameter<CustomAccessDeniedException> parameter) {
getElement().setText(parameter.hasCustomMessage()
? parameter.getCustomMessage() : "Access denied.");
return HttpStatusCode.UNAUTHORIZED.getCode();
}
}
Note that the exception class named by rerouteToError() is
instantiated reflectively when access is denied, so it needs to have a public
no-arg constructor. That is why CustomAccessDeniedException above
declares one explicitly: giving the exception only a message constructor
would remove the implicit no-arg constructor and make the access denied
navigation fail with an internal server error instead of showing the error
view.
- Since:
- 24.3
-
Optional Element Summary
Optional ElementsModifier and TypeOptional ElementDescriptionClass<? extends RuntimeException> Reroute access denied error by the given exception.
-
Element Details
-
rerouteToError
Class<? extends RuntimeException> rerouteToErrorReroute access denied error by the given exception. Exception isAccessDeniedExceptionby default. It can be changed to other exception likeNotFoundExceptionor any other exception mapped toHasErrorParametererror view.Exception class needs to have default no-arg constructor, since the exception is instantiated by
BeforeEvent.rerouteToError(Class, String)when access is denied. The exception does not need to carry the reason for the denial: the reason is passed separately to the error view and is available there asErrorParameter.getCustomMessage().- Returns:
- Type of the access denied exception for the access denied error view.
- Default:
com.vaadin.flow.router.AccessDeniedException.class
-