Class VaadinAwareSecurityContextHolderStrategy

java.lang.Object
com.vaadin.flow.spring.security.VaadinAwareSecurityContextHolderStrategy
All Implemented Interfaces:
org.springframework.security.core.context.SecurityContextHolderStrategy

public final class VaadinAwareSecurityContextHolderStrategy extends Object implements org.springframework.security.core.context.SecurityContextHolderStrategy
A strategy that uses an available VaadinSession for retrieving the security context.

Falls back to the default thread specific security context when no vaadinSession is available.

The thread specific security context is stored in a static field, shared by all instances of this class, mirroring Spring Security's own ThreadLocalSecurityContextHolderStrategy. SecurityContextHolder holds one strategy per classloader, while a strategy is contributed as a bean of an application context. Several application contexts in the same JVM, for example the contexts cached by the Spring test framework, would therefore each get an instance with its own store: the instance installed last serves SecurityContextHolder, while components wired to the strategy bean of another context, such as the method security interceptors, keep reading that context's instance. Sharing the store makes all instances interchangeable, so that it does not matter which one is installed.

Since:
19.0
  • Constructor Details

    • VaadinAwareSecurityContextHolderStrategy

      public VaadinAwareSecurityContextHolderStrategy()
      Creates the strategy.
  • Method Details

    • clearContext

      public void clearContext()
      Specified by:
      clearContext in interface org.springframework.security.core.context.SecurityContextHolderStrategy
    • getContext

      public @NonNull org.springframework.security.core.context.SecurityContext getContext()
      Specified by:
      getContext in interface org.springframework.security.core.context.SecurityContextHolderStrategy
    • setContext

      public void setContext(@NonNull org.springframework.security.core.context.SecurityContext securityContext)
      Specified by:
      setContext in interface org.springframework.security.core.context.SecurityContextHolderStrategy
    • createEmptyContext

      public @NonNull org.springframework.security.core.context.SecurityContext createEmptyContext()
      Specified by:
      createEmptyContext in interface org.springframework.security.core.context.SecurityContextHolderStrategy