Class EndpointInvoker

java.lang.Object
com.vaadin.hilla.EndpointInvoker

public class EndpointInvoker extends Object
Handles invocation of endpoint methods after checking the user has proper access.

This class is a generic invoker that does not have knowledge of HTTP requests or the context that the method is being invoked in.

For internal use only. May be renamed or removed in a future release.

  • Constructor Details

    • EndpointInvoker

      public EndpointInvoker(org.springframework.context.ApplicationContext applicationContext, @Qualifier("hillaEndpointObjectMapper") tools.jackson.databind.ObjectMapper endpointObjectMapper, ExplicitNullableTypeChecker explicitNullableTypeChecker, jakarta.servlet.ServletContext servletContext, EndpointRegistry endpointRegistry)
      Creates an instance of this bean.
      Parameters:
      applicationContext - The Spring application context
      endpointObjectMapper - The object mapper to be used for serialization and deserialization of request and response bodies. To override the mapper, use the EndpointController.ENDPOINT_MAPPER_FACTORY_BEAN_QUALIFIER qualifier on a JacksonObjectMapperFactory bean definition.
      explicitNullableTypeChecker - the method parameter and return value type checker to verify that null values are explicit
      servletContext - the servlet context
      endpointRegistry - the registry used to store endpoint information
  • Method Details

    • getReturnType

      public Class<?> getReturnType(String endpointName, String methodName)
      Gets the return type of the given method.
      Parameters:
      endpointName - the name of the endpoint
      methodName - the name of the method
    • invoke

      public Object invoke(String endpointName, String methodName, tools.jackson.databind.node.ObjectNode body, Principal principal, Function<String,Boolean> rolesChecker) throws EndpointInvocationException.EndpointHttpException
      Invoke the given endpoint method with the given parameters if the user has access to do so.
      Parameters:
      endpointName - the name of the endpoint
      methodName - the name of the method in the endpoint
      body - optional request body, that should be specified if the method called has parameters
      principal - the user principal object
      rolesChecker - a function for checking if a user is in a given role
      Returns:
      the return value of the invoked endpoint method, wrapped in a response entity
      Throws:
      EndpointInvocationException.EndpointHttpException - if thrown by the endpoint
    • getVaadinEndpointData

      Throws:
      EndpointInvocationException.EndpointNotFoundException
    • checkAccess

      public String checkAccess(EndpointRegistry.VaadinEndpointData endpointData, Method methodToInvoke, Principal principal, Function<String,Boolean> rolesChecker)
      Checks that the given user is allowed to call the given endpoint method.

      When the access is denied and an AuthorizationEventPublisher bean is available, an AuthorizationDeniedEvent carrying an EndpointInvocation is published, so that endpoint calls can be audited the same way as Spring method security invocations. The event is published for denied calls of unauthenticated users as well, and, like in Spring, the authentication it supplies is the anonymous authentication of the user rather than null.

      Parameters:
      endpointData - the data of the endpoint to check
      methodToInvoke - the endpoint method to check
      principal - the user principal object
      rolesChecker - a function for checking if a user is in a given role
      Returns:
      an error message if the access is denied, null otherwise