View Javadoc

1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one
3    * or more contributor license agreements.  See the NOTICE file
4    * distributed with this work for additional information
5    * regarding copyright ownership.  The ASF licenses this file
6    * to you under the Apache License, Version 2.0 (the
7    * "License"); you may not use this file except in compliance
8    * with the License.  You may obtain a copy of the License at
9    *
10   *     http://www.apache.org/licenses/LICENSE-2.0
11   *
12   * Unless required by applicable law or agreed to in writing,
13   * software distributed under the License is distributed on an
14   * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15   * KIND, either express or implied.  See the License for the
16   * specific language governing permissions and limitations
17   * under the License.
18   */
19  package org.apache.shiro.authz.annotation;
20  
21  import java.lang.annotation.ElementType;
22  import java.lang.annotation.Retention;
23  import java.lang.annotation.RetentionPolicy;
24  import java.lang.annotation.Target;
25  
26  /**
27   * Requires the current Subject to have been authenticated <em>during their current session</em> for the annotated
28   * class/instance/method to be accessed or invoked.  This is <em>more</em> restrictive than the
29   * {@link RequiresUser RequiresUser} annotation.
30   * <p/>
31   * This annotation basically ensures that
32   * <code>{@link org.apache.shiro.subject.Subject subject}.{@link org.apache.shiro.subject.Subject#isAuthenticated() isAuthenticated()} === true</code>
33   * <p/>
34   * See the {@link RequiresUser RequiresUser} and
35   * {@link org.apache.shiro.authc.RememberMeAuthenticationToken RememberMeAuthenticationToken} JavaDoc for an
36   * explaination of why these two states are considered different.
37   *
38   * @see RequiresUser
39   * @see RequiresGuest
40   *
41   * @since 0.9.0
42   */
43  @Target({ElementType.TYPE, ElementType.METHOD})
44  @Retention(RetentionPolicy.RUNTIME)
45  public @interface RequiresAuthentication {
46  }