com.sksamuel.scruffy.security.authorization

Authorizer

trait Authorizer extends AnyRef

An Authorizer is responsible for determining if a given user is able to perform the requested action (in this case process the requested URL).

The Authorizer is passed the current request. The authorizer can inspect the Principal object if an AuthenciationStrategy was invoked prior. Alternatively, it may determine authorization based on some request-level criteria, such as ip address.

If the request is authorized then the Authorizer should continue the request pipeline. If the request is not authorized then the Authorizer would normally return an appropriate response, although it can choose to do anything it wishes.

How the Authorizer determines access is dependent on the implementation.

For example, the AccessListAuthorizer authorizes requests based on a given list of Principals. If the principals list does not contain the given Principal then a 403 is returned.

An AllAccessAuthorizer authorizes all requests. This is useful when you have site wide authorization but wish to enable public access to a certain endpoint.

Usually you will want to implement a custom Authorizer, which may check a user for a role, or some similar mechanism. To implement a custom Authorizer, extend from Authorizer implementing the authorization check.

Linear Supertypes
AnyRef, Any
Known Subclasses
Ordering
  1. Alphabetic
  2. By inheritance
Inherited
  1. Authorizer
  2. AnyRef
  3. Any
  1. Hide All
  2. Show all
Learn more about member selection
Visibility
  1. Public
  2. All

Abstract Value Members

  1. abstract def authorize(req: HttpRequest, f: (HttpRequest) ⇒ Future[HttpResponse]): Future[HttpResponse]

Concrete Value Members

  1. final def !=(arg0: AnyRef): Boolean

    Definition Classes
    AnyRef
  2. final def !=(arg0: Any): Boolean

    Definition Classes
    Any
  3. final def ##(): Int

    Definition Classes
    AnyRef → Any
  4. final def ==(arg0: AnyRef): Boolean

    Definition Classes
    AnyRef
  5. final def ==(arg0: Any): Boolean

    Definition Classes
    Any
  6. final def asInstanceOf[T0]: T0

    Definition Classes
    Any
  7. def clone(): AnyRef

    Attributes
    protected[java.lang]
    Definition Classes
    AnyRef
    Annotations
    @throws( ... )
  8. final def eq(arg0: AnyRef): Boolean

    Definition Classes
    AnyRef
  9. def equals(arg0: Any): Boolean

    Definition Classes
    AnyRef → Any
  10. def finalize(): Unit

    Attributes
    protected[java.lang]
    Definition Classes
    AnyRef
    Annotations
    @throws( classOf[java.lang.Throwable] )
  11. final def getClass(): Class[_]

    Definition Classes
    AnyRef → Any
  12. def hashCode(): Int

    Definition Classes
    AnyRef → Any
  13. final def isInstanceOf[T0]: Boolean

    Definition Classes
    Any
  14. final def ne(arg0: AnyRef): Boolean

    Definition Classes
    AnyRef
  15. final def notify(): Unit

    Definition Classes
    AnyRef
  16. final def notifyAll(): Unit

    Definition Classes
    AnyRef
  17. final def synchronized[T0](arg0: ⇒ T0): T0

    Definition Classes
    AnyRef
  18. def toString(): String

    Definition Classes
    AnyRef → Any
  19. final def wait(): Unit

    Definition Classes
    AnyRef
    Annotations
    @throws( ... )
  20. final def wait(arg0: Long, arg1: Int): Unit

    Definition Classes
    AnyRef
    Annotations
    @throws( ... )
  21. final def wait(arg0: Long): Unit

    Definition Classes
    AnyRef
    Annotations
    @throws( ... )

Inherited from AnyRef

Inherited from Any

Ungrouped