1
0

Split into per-article modules and add the method-security module

Moves the existing virtual-thread/context-propagation project into
context-propagation/ and adds method-security/ for the Spring Security 7
method-security article: nine runnable demos, fourteen assertions, and every
transcript the article quotes, regenerated by scripts/run-all.sh.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RSrsDSRKVsY588yFiMJMo9
This commit is contained in:
2026-08-25 02:01:29 +00:00
parent 9f950bffa9
commit 5e9e7f1b12
65 changed files with 4088 additions and 119 deletions

View File

@@ -0,0 +1,24 @@
==============================================================================
Demo 9 -- #parameterName and the -parameters compiler flag
==============================================================================
compiled with -parameters : true
byParameterName param[0] : owner
byParameterAlias param[0] : owner (annotated @P("o"))
SLF4J(W): No SLF4J providers were found.
SLF4J(W): Defaulting to no-operation (NOP) logger implementation
SLF4J(W): See https://www.slf4j.org/codes.html#noProviders for further details.
alice calling with her own name
-------------------------------
#owner == authentication.name ALLOWED -> ok
#o == authentication.name (@P("o")) ALLOWED -> ok
alice calling with somebody else's name
---------------------------------------
#owner == authentication.name DENIED -> AuthorizationDeniedException: Access Denied
#o == authentication.name (@P("o")) DENIED -> AuthorizationDeniedException: Access Denied
Without -parameters the first expression denies BOTH calls -- it fails
closed, which is the good direction, but it fails silently in the sense
that nothing tells you the rule is not the rule you wrote. @P("o") does
not depend on the flag, because the name is in the class file either way.