lucee.Componentmodels.validators.AuthValidator
Copyright since 2016 by Ortus Solutions, Corp www.ortussolutions.com --- This is the core validator which leverages any Authentication Service that implements cbsecurity.models.interfaces.IAuthService and any User that implements cbsecurity.models.interfaces.IAuthUser
Property Summary | ||||
---|---|---|---|---|
type | property | default | serializable | required |
any
|
cbSecurity
|
true
|
false
|
|
any
|
log
|
true
|
false
|
Method Summary | |
---|---|
struct
|
annotationValidator(any securedValue, any controller)
This function is called once access to a handler/action is detected. |
struct
|
ruleValidator(any rule, any controller)
This function is called once an incoming event matches a security rule. |
private any
|
validateSecurity([string permissions=''], [string roles=''])
Validate Security on the user. |
Methods inherited from class lucee.Component |
---|
None |
Property Detail |
---|
access
- publicrequired
- falsereturntype
- anyinject
- CBSecurity@cbSecurityserializable
- trueaccess
- publicrequired
- falsereturntype
- anyinject
- logbox:logger:{this}serializable
- trueMethod Detail |
---|
This function is called once access to a handler/action is detected. You will receive the secured annotation value and an instance of the ColdBox Controller You must return a struct with three keys: - allow:boolean True, user can continue access, false, invalid access actions will ensue - type:string(authentication|authorization) The type of block that ocurred. Either an authentication or an authorization issue. - messages:string Info/debug messages
securedValue
controller
This function is called once an incoming event matches a security rule. You will receive the security rule that matched and an instance of the ColdBox controller. You must return a struct with three keys: - allow:boolean True, user can continue access, false, invalid access actions will ensue - type:string(authentication|authorization) The type of block that ocurred. Either an authentication or an authorization issue. - messages:string Info/debug messages
rule
controller
Validate Security on the user
permissions
- The secured value of the annotation or the rule permissionsroles
- Rule roles