Annotation Interface AccessDeniedErrorRouter


@Retention(RUNTIME) @Target(TYPE) public @interface AccessDeniedErrorRouter
Annotation for customizing route specific rerouting of access denied error in AnnotatedViewAccessChecker. Annotation is to be used together with @Route, or if present, together with access annotation listed here:
  • @AnonymousAllowed
  • @PermitAll
  • @RolesAllowed
  • @DenyAll
For example, following TestView and SubView routes would reroute user without "admin" role to CustomAccessDeniedError error page:
 @AccessDeniedErrorRouter(rerouteToError = CustomAccessDeniedException.class)
 @RolesAllowed("admin")
 @Route("test")
 public class TestView extends Div {
 }

 @AccessDeniedErrorRouter(rerouteToError = CustomAccessDeniedException.class)
 @RolesAllowed("admin")
 public class ParentView extends Div {
 }

 @Route("subview")
 public class SubView extends ParentView {
 }

 public class CustomAccessDeniedException extends RuntimeException {
     public CustomAccessDeniedException() {
     }

     public CustomAccessDeniedException(String message) {
         super(message);
     }
 }

 @Tag(Tag.DIV)
 public class CustomAccessDeniedError
         implements HasErrorParameter<CustomAccessDeniedException> {

     @Override
     public int setErrorParameter(BeforeEnterEvent event,
             ErrorParameter<CustomAccessDeniedException> parameter) {
         getElement().setText(parameter.hasCustomMessage()
                 ? parameter.getCustomMessage() : "Access denied.");
         return HttpStatusCode.UNAUTHORIZED.getCode();
     }
 }
 

Note that the exception class named by rerouteToError() is instantiated reflectively when access is denied, so it needs to have a public no-arg constructor. That is why CustomAccessDeniedException above declares one explicitly: giving the exception only a message constructor would remove the implicit no-arg constructor and make the access denied navigation fail with an internal server error instead of showing the error view.

Since:
24.3
  • Optional Element Summary

    Optional Elements
    Modifier and Type
    Optional Element
    Description
    Reroute access denied error by the given exception.
  • Element Details

    • rerouteToError

      Class<? extends RuntimeException> rerouteToError
      Reroute access denied error by the given exception. Exception is AccessDeniedException by default. It can be changed to other exception like NotFoundException or any other exception mapped to HasErrorParameter error view.

      Exception class needs to have default no-arg constructor, since the exception is instantiated by BeforeEvent.rerouteToError(Class, String) when access is denied. The exception does not need to carry the reason for the denial: the reason is passed separately to the error view and is available there as ErrorParameter.getCustomMessage().

      Returns:
      Type of the access denied exception for the access denied error view.
      Default:
      com.vaadin.flow.router.AccessDeniedException.class