Package org.jppf.jmxremote
Interface JMXAuthorizationChecker
- All Known Implementing Classes:
JMXAuthorizationCheckerAdapter,JMXAuthorizationDeniedAdapter
public interface JMXAuthorizationChecker
This interface represents a set of authorization checks for a given authenticated subject.
A check is available for each method available in the MBeanServerConnection interface
and is implemented as a method whose name is made of the "check" prefix, followed by the name of the method to check.
An authorization failure is raised by throwing an exception in a checkXXX() method.
- Author:
- Laurent Cohen
-
Method Summary
Modifier and TypeMethodDescriptionvoidcheckAddNotificationListener(ObjectName name, NotificationListener listener, NotificationFilter filter, Object handback) Check that the subject can invoke theMBeanServerConnection.addNotificationListener(ObjectName, NotificationListener, NotificationFilter, Object)method on the mbean server.voidcheckAddNotificationListener(ObjectName name, ObjectName listener, NotificationFilter filter, Object handback) Check that the subject can invoke theMBeanServerConnection.addNotificationListener(ObjectName, ObjectName, NotificationFilter, Object)method on the mbean server.voidcheckCreateMBean(String className, ObjectName name) Check that the subject can invoke theMBeanServerConnection.createMBean(String, ObjectName)method on the mbean server.voidcheckCreateMBean(String className, ObjectName name, Object[] params, String[] signature) Check that the subject can invoke theMBeanServerConnection.createMBean(String, ObjectName, Object[], String[])method on the mbean server.voidcheckCreateMBean(String className, ObjectName name, ObjectName loaderName) Check that the subject can invoke theMBeanServerConnection.createMBean(String, ObjectName, ObjectName)method on the mbean server.voidcheckCreateMBean(String className, ObjectName name, ObjectName loaderName, Object[] params, String[] signature) Check that the subject can invoke theMBeanServerConnection.createMBean(String, ObjectName, ObjectName, Object[], String[])method on the mbean server.voidcheckGetAttribute(ObjectName name, String attribute) Check that the subject can invoke theMBeanServerConnection.getAttribute(ObjectName, String)method on the mbean server.voidcheckGetAttributes(ObjectName name, String[] attributes) Check that the subject can invoke theMBeanServerConnection.getAttributes(ObjectName, String[])method on the mbean server.voidCheck that the subject can invoke theMBeanServerConnection.getDefaultDomain()method on the mbean server.voidCheck that the subject can invoke theMBeanServerConnection.getDomains()method on the mbean server.voidCheck that the subject can invoke theMBeanServerConnection.getMBeanCount()method on the mbean server.voidcheckGetMBeanInfo(ObjectName name) Check that the subject can invoke theMBeanServerConnection.getMBeanInfo(ObjectName)method on the mbean server.voidCheck that the subject can invoke theMBeanServerConnection.getObjectInstance(ObjectName)method on the mbean server.voidcheckInvoke(ObjectName name, String operationName, Object[] params, String[] signature) Check that the subject can invoke theMBeanServerConnection.invoke(ObjectName, String, Object[], String[])method on the mbean server.voidcheckIsInstanceOf(ObjectName name, String className) Check that the subject can invoke theMBeanServerConnection.isInstanceOf(ObjectName, String)method on the mbean server.voidcheckIsRegistered(ObjectName name) Check that the subject can invoke theMBeanServerConnection.isRegistered(ObjectName)method on the mbean server.voidcheckQueryMBeans(ObjectName name, QueryExp query) Check that the subject can invoke theMBeanServerConnection.queryMBeans(ObjectName, QueryExp)method on the mbean server.voidcheckQueryNames(ObjectName name, QueryExp query) Check that the subject can invoke theMBeanServerConnection.queryNames(ObjectName, QueryExp)method on the mbean server.voidcheckRemoveNotificationListener(ObjectName name, NotificationListener listener) Check that the subject can invoke theMBeanServerConnection.removeNotificationListener(ObjectName, NotificationListener)method on the mbean server.voidcheckRemoveNotificationListener(ObjectName name, NotificationListener listener, NotificationFilter filter, Object handback) Check that the subject can invoke theMBeanServerConnection.removeNotificationListener(ObjectName, NotificationListener, NotificationFilter, Object)method on the mbean server.voidcheckRemoveNotificationListener(ObjectName name, ObjectName listener) Check that the subject can invoke theMBeanServerConnection.removeNotificationListener(ObjectName, ObjectName)method on the mbean server.voidcheckRemoveNotificationListener(ObjectName name, ObjectName listener, NotificationFilter filter, Object handback) Check that the subject can invoke theMBeanServerConnection.removeNotificationListener(ObjectName, ObjectName, NotificationFilter, Object)method on the mbean server.voidcheckSetAttribute(ObjectName name, Attribute attribute) Check that the subject can invoke theMBeanServerConnection.setAttribute(ObjectName, Attribute)method on the mbean server.voidcheckSetAttributes(ObjectName name, AttributeList attributes) Check that the subject can invoke theMBeanServerConnection.setAttributes(ObjectName, AttributeList)method on the mbean server.voidCheck that the subject can invoke theMBeanServerConnection.unregisterMBean(ObjectName)method on the mbean server.Get the authenticated subject to check for authorization.voidsetSubject(Subject subject) Set the authenticated subject to check for authorization.
-
Method Details
-
getSubject
Subject getSubject()Get the authenticated subject to check for authorization.- Returns:
- the authenticated
Subject, if any.
-
setSubject
Set the authenticated subject to check for authorization.- Parameters:
subject- the authenticatedSubjectto set.
-
checkCreateMBean
Check that the subject can invoke theMBeanServerConnection.createMBean(String, ObjectName)method on the mbean server.- Parameters:
className- the class name of the MBean to instantiate.name- the object name of the MBean. May be null.- Throws:
Exception- if the subject is not authorized.
-
checkCreateMBean
Check that the subject can invoke theMBeanServerConnection.createMBean(String, ObjectName, ObjectName)method on the mbean server.- Parameters:
className- the class name of the MBean to be instantiated.name- the object name of the MBean. May be null.loaderName- the object name of the class loader to be used.- Throws:
Exception- if the subject is not authorized.
-
checkCreateMBean
void checkCreateMBean(String className, ObjectName name, Object[] params, String[] signature) throws Exception Check that the subject can invoke theMBeanServerConnection.createMBean(String, ObjectName, Object[], String[])method on the mbean server.- Parameters:
className- the class name of the MBean to instantiate.name- the object name of the MBean. May be null.params- an array containing the parameters of the constructor to invoke.signature- an array containing the signature of the constructor to invoke.- Throws:
Exception- if the subject is not authorized.
-
checkCreateMBean
void checkCreateMBean(String className, ObjectName name, ObjectName loaderName, Object[] params, String[] signature) throws Exception Check that the subject can invoke theMBeanServerConnection.createMBean(String, ObjectName, ObjectName, Object[], String[])method on the mbean server.- Parameters:
className- The class name of the MBean to instantiate.name- the object name of the MBean. May be null.loaderName- the object name of the class loader to use.params- an array containing the parameters of the constructor to invoke.signature- an array containing the signature of the constructor to invoke.- Throws:
Exception- if the subject is not authorized.
-
checkUnregisterMBean
Check that the subject can invoke theMBeanServerConnection.unregisterMBean(ObjectName)method on the mbean server.- Parameters:
name- the object name of the MBean to unregister.- Throws:
Exception- if the subject is not authorized.
-
checkGetObjectInstance
Check that the subject can invoke theMBeanServerConnection.getObjectInstance(ObjectName)method on the mbean server.- Parameters:
name- the object name of the MBean.- Throws:
Exception- if the subject is not authorized.
-
checkQueryMBeans
Check that the subject can invoke theMBeanServerConnection.queryMBeans(ObjectName, QueryExp)method on the mbean server.- Parameters:
name- the object name pattern identifying the MBeans to retrieve.query- the query expression to apply for selecting MBeans.- Throws:
Exception- if the subject is not authorized.
-
checkQueryNames
Check that the subject can invoke theMBeanServerConnection.queryNames(ObjectName, QueryExp)method on the mbean server.- Parameters:
name- the object name pattern identifying the MBean names to retrieve.query- the query expression to apply for selecting MBeans.- Throws:
Exception- if the subject is not authorized.
-
checkIsRegistered
Check that the subject can invoke theMBeanServerConnection.isRegistered(ObjectName)method on the mbean server.- Parameters:
name- the object name of the MBean to check.- Throws:
Exception- if the subject is not authorized.
-
checkGetMBeanCount
Check that the subject can invoke theMBeanServerConnection.getMBeanCount()method on the mbean server.- Throws:
Exception- if the subject is not authorized.
-
checkGetAttribute
Check that the subject can invoke theMBeanServerConnection.getAttribute(ObjectName, String)method on the mbean server.- Parameters:
name- the object name of the MBean from which the attribute is to be retrieved.attribute- A String specifying the name of the attribute to retrieve.- Throws:
Exception- if the subject is not authorized.
-
checkGetAttributes
Check that the subject can invoke theMBeanServerConnection.getAttributes(ObjectName, String[])method on the mbean server.- Parameters:
name- the object name of the MBean from which the attributes are retrieved.attributes- a list of the attributes to retrieve.- Throws:
Exception- if the subject is not authorized.
-
checkSetAttribute
Check that the subject can invoke theMBeanServerConnection.setAttribute(ObjectName, Attribute)method on the mbean server.- Parameters:
name- the name of the MBean within which the attribute is to be set.attribute- The identification of the attribute to set and the value to set it to.- Throws:
Exception- if the subject is not authorized.
-
checkSetAttributes
Check that the subject can invoke theMBeanServerConnection.setAttributes(ObjectName, AttributeList)method on the mbean server.- Parameters:
name- The object name of the MBean within which the attributes are to be set.attributes- A list of attributes: the identification of the attributes to set and the values to set them to.- Throws:
Exception- if the subject is not authorized.
-
checkInvoke
void checkInvoke(ObjectName name, String operationName, Object[] params, String[] signature) throws Exception Check that the subject can invoke theMBeanServerConnection.invoke(ObjectName, String, Object[], String[])method on the mbean server.- Parameters:
name- the object name of the MBean on which the method is invoked.operationName- the name of the operation to invoke.params- an array containing the parameters to set when the operation is invoked.signature- an array containing the signature of the operation, an array of class names in the format returned byClass.getName().- Throws:
Exception- if the subject is not authorized.
-
checkGetDefaultDomain
Check that the subject can invoke theMBeanServerConnection.getDefaultDomain()method on the mbean server.- Throws:
Exception- if the subject is not authorized.
-
checkGetDomains
Check that the subject can invoke theMBeanServerConnection.getDomains()method on the mbean server.- Throws:
Exception- if the subject is not authorized.
-
checkAddNotificationListener
void checkAddNotificationListener(ObjectName name, NotificationListener listener, NotificationFilter filter, Object handback) throws Exception Check that the subject can invoke theMBeanServerConnection.addNotificationListener(ObjectName, NotificationListener, NotificationFilter, Object)method on the mbean server.- Parameters:
name- the name of the MBean on which the listener should be added.listener- the listener object which will handle the notifications emitted by the registered MBean.filter- the filter object.handback- the context to send to the listener when a notification is emitted.- Throws:
Exception- if the subject is not authorized.
-
checkAddNotificationListener
void checkAddNotificationListener(ObjectName name, ObjectName listener, NotificationFilter filter, Object handback) throws Exception Check that the subject can invoke theMBeanServerConnection.addNotificationListener(ObjectName, ObjectName, NotificationFilter, Object)method on the mbean server.- Parameters:
name- the name of the MBean on which the listener should be added.listener- the object name of the listener object which will handle the notifications emitted by the registered MBean.filter- the filter object.handback- the context to send to the listener when a notification is emitted.- Throws:
Exception- if the subject is not authorized.
-
checkRemoveNotificationListener
Check that the subject can invoke theMBeanServerConnection.removeNotificationListener(ObjectName, ObjectName)method on the mbean server.- Parameters:
name- the name of the MBean on which the listener should be added.listener- the object name of the listener object which will handle the notifications emitted by the registered MBean.- Throws:
Exception- if the subject is not authorized.
-
checkRemoveNotificationListener
void checkRemoveNotificationListener(ObjectName name, ObjectName listener, NotificationFilter filter, Object handback) throws Exception Check that the subject can invoke theMBeanServerConnection.removeNotificationListener(ObjectName, ObjectName, NotificationFilter, Object)method on the mbean server.- Parameters:
name- the name of the MBean on which the listener should be removed.listener- the object name of the listener to remove.filter- the filter that was specified when the listener was added.handback- the handback that was specified when the listener was added.- Throws:
Exception- if the subject is not authorized.
-
checkRemoveNotificationListener
void checkRemoveNotificationListener(ObjectName name, NotificationListener listener) throws Exception Check that the subject can invoke theMBeanServerConnection.removeNotificationListener(ObjectName, NotificationListener)method on the mbean server.- Parameters:
name- the name of the MBean on which the listener should be removed.listener- the listener object to remove.- Throws:
Exception- if the subject is not authorized.
-
checkRemoveNotificationListener
void checkRemoveNotificationListener(ObjectName name, NotificationListener listener, NotificationFilter filter, Object handback) throws Exception Check that the subject can invoke theMBeanServerConnection.removeNotificationListener(ObjectName, NotificationListener, NotificationFilter, Object)method on the mbean server.- Parameters:
name- the name of the MBean on which the listener should be removed.listener- the listener object to remove.filter- the filter that was specified when the listener was added.handback- the handback that was specified when the listener was added.- Throws:
Exception- if the subject is not authorized.
-
checkGetMBeanInfo
Check that the subject can invoke theMBeanServerConnection.getMBeanInfo(ObjectName)method on the mbean server.- Parameters:
name- the name of the MBean to analyze- Throws:
Exception- if the subject is not authorized.
-
checkIsInstanceOf
Check that the subject can invoke theMBeanServerConnection.isInstanceOf(ObjectName, String)method on the mbean server.- Parameters:
name- the object name of the MBean.className- the name of the class.- Throws:
Exception- if the subject is not authorized.
-