1

我正在尝试使用 Restlet 实现一个 RESTful API,除了基本的角色和方法授权器之外,我几乎没有发现任何东西。我已经在数据库中存储了用户可以访问的那些路由的路由和方法。我现在遇到的问题是如何在 Authorizer 中获取路径。这是我需要收集的资源吗?我到底应该如何路由到授权人?我已经发布了到目前为止的内容,我正在查看我的授权人如何获取路径或资源。感谢您提供任何信息,我查看了书籍和许多通用示例,并没有找到我正在寻找的东西。

我的路由应用程序:

public class MyRoutingApp extends org.restlet.Application {

    @Override  
    public synchronized Restlet createInboundRoot() { 

        Context context = getContext();
        Router router = new Router(context);

        router.attach("/user", Users.class);
        router.attach("/post", Posts.class);
        router.attach("/comment", Comments.class);

        ChallengeAuthenticator authenticator = new ChallengeAuthenticator( 
                context, ChallengeScheme.HTTP_BASIC, "My test realm" );

        //create Verifier to ensure that the user is authenicated
        MyVerifier verifier = new MySecretVerifier();
        //grab user Roles and add them to the request
        MyEnroler enroler = new MyEnroler();

        authenticator.setVerifier( verifier );
        authenticator.setEnroler( enroler );

        //Looks up if user can be allowed to resource
        MyAuthorizer authorizer = new MyAuthorizer();
        authorizer.setNext( router );

        authenticator.setNext( authorizer );
        return authenticator; 
    }
}

我的授权人:

public class MyAuthorizer extends Authorizer {

    @Override
    protected boolean authorize( Request request, Response response ) {

        //has the security roles and user from verifier and enroler
        ClientInfo info = request.getClientInfo();
        //get http method
        Method method = request.getMethod();

        //need to get the route or resource user is attempting to access
        //allow or disallow access based on roles and method
    }
}
4

1 回答 1

2

目标资源 URI 可通过 Request#getResouceRef().getRemainingPart() 获得。

于 2013-05-14T20:59:05.677 回答