You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@tuscany.apache.org by sl...@apache.org on 2011/10/12 13:58:28 UTC

svn commit: r1182320 - in /tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250: ./ src/ src/main/ src/main/java/ src/main/java/org/ src/main/java/org/apache/ src/main/java/org/apache/tuscany/ src/main/java/org/apache/tuscany/sca/ src/main/java/or...

Author: slaws
Date: Wed Oct 12 11:58:27 2011
New Revision: 1182320

URL: http://svn.apache.org/viewvc?rev=1182320&view=rev
Log:
TUSCANY-3960 - start porting JSR250 support from 1.x

Added:
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/LICENSE
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/NOTICE
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/pom.xml
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/policy/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/policy/security/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/policy/security/jsr250/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/policy/security/jsr250/JSR250PolicyProcessor.java
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/resources/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/resources/META-INF/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/resources/META-INF/services/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/resources/META-INF/services/org.apache.tuscany.sca.implementation.java.introspect.JavaClassVisitor
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/policy/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/policy/security/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/policy/security/jsr250/   (with props)
    tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/policy/security/jsr250/PolicyProcessorTestCase.java

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/
------------------------------------------------------------------------------
--- svn:ignore (added)
+++ svn:ignore Wed Oct 12 11:58:27 2011
@@ -0,0 +1,4 @@
+.classpath
+.project
+.settings
+target

Added: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/LICENSE
URL: http://svn.apache.org/viewvc/tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/LICENSE?rev=1182320&view=auto
==============================================================================
--- tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/LICENSE (added)
+++ tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/LICENSE Wed Oct 12 11:58:27 2011
@@ -0,0 +1,205 @@
+
+                                 Apache License
+                           Version 2.0, January 2004
+                        http://www.apache.org/licenses/
+
+   TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
+
+   1. Definitions.
+
+      "License" shall mean the terms and conditions for use, reproduction,
+      and distribution as defined by Sections 1 through 9 of this document.
+
+      "Licensor" shall mean the copyright owner or entity authorized by
+      the copyright owner that is granting the License.
+
+      "Legal Entity" shall mean the union of the acting entity and all
+      other entities that control, are controlled by, or are under common
+      control with that entity. For the purposes of this definition,
+      "control" means (i) the power, direct or indirect, to cause the
+      direction or management of such entity, whether by contract or
+      otherwise, or (ii) ownership of fifty percent (50%) or more of the
+      outstanding shares, or (iii) beneficial ownership of such entity.
+
+      "You" (or "Your") shall mean an individual or Legal Entity
+      exercising permissions granted by this License.
+
+      "Source" form shall mean the preferred form for making modifications,
+      including but not limited to software source code, documentation
+      source, and configuration files.
+
+      "Object" form shall mean any form resulting from mechanical
+      transformation or translation of a Source form, including but
+      not limited to compiled object code, generated documentation,
+      and conversions to other media types.
+
+      "Work" shall mean the work of authorship, whether in Source or
+      Object form, made available under the License, as indicated by a
+      copyright notice that is included in or attached to the work
+      (an example is provided in the Appendix below).
+
+      "Derivative Works" shall mean any work, whether in Source or Object
+      form, that is based on (or derived from) the Work and for which the
+      editorial revisions, annotations, elaborations, or other modifications
+      represent, as a whole, an original work of authorship. For the purposes
+      of this License, Derivative Works shall not include works that remain
+      separable from, or merely link (or bind by name) to the interfaces of,
+      the Work and Derivative Works thereof.
+
+      "Contribution" shall mean any work of authorship, including
+      the original version of the Work and any modifications or additions
+      to that Work or Derivative Works thereof, that is intentionally
+      submitted to Licensor for inclusion in the Work by the copyright owner
+      or by an individual or Legal Entity authorized to submit on behalf of
+      the copyright owner. For the purposes of this definition, "submitted"
+      means any form of electronic, verbal, or written communication sent
+      to the Licensor or its representatives, including but not limited to
+      communication on electronic mailing lists, source code control systems,
+      and issue tracking systems that are managed by, or on behalf of, the
+      Licensor for the purpose of discussing and improving the Work, but
+      excluding communication that is conspicuously marked or otherwise
+      designated in writing by the copyright owner as "Not a Contribution."
+
+      "Contributor" shall mean Licensor and any individual or Legal Entity
+      on behalf of whom a Contribution has been received by Licensor and
+      subsequently incorporated within the Work.
+
+   2. Grant of Copyright License. Subject to the terms and conditions of
+      this License, each Contributor hereby grants to You a perpetual,
+      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+      copyright license to reproduce, prepare Derivative Works of,
+      publicly display, publicly perform, sublicense, and distribute the
+      Work and such Derivative Works in Source or Object form.
+
+   3. Grant of Patent License. Subject to the terms and conditions of
+      this License, each Contributor hereby grants to You a perpetual,
+      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+      (except as stated in this section) patent license to make, have made,
+      use, offer to sell, sell, import, and otherwise transfer the Work,
+      where such license applies only to those patent claims licensable
+      by such Contributor that are necessarily infringed by their
+      Contribution(s) alone or by combination of their Contribution(s)
+      with the Work to which such Contribution(s) was submitted. If You
+      institute patent litigation against any entity (including a
+      cross-claim or counterclaim in a lawsuit) alleging that the Work
+      or a Contribution incorporated within the Work constitutes direct
+      or contributory patent infringement, then any patent licenses
+      granted to You under this License for that Work shall terminate
+      as of the date such litigation is filed.
+
+   4. Redistribution. You may reproduce and distribute copies of the
+      Work or Derivative Works thereof in any medium, with or without
+      modifications, and in Source or Object form, provided that You
+      meet the following conditions:
+
+      (a) You must give any other recipients of the Work or
+          Derivative Works a copy of this License; and
+
+      (b) You must cause any modified files to carry prominent notices
+          stating that You changed the files; and
+
+      (c) You must retain, in the Source form of any Derivative Works
+          that You distribute, all copyright, patent, trademark, and
+          attribution notices from the Source form of the Work,
+          excluding those notices that do not pertain to any part of
+          the Derivative Works; and
+
+      (d) If the Work includes a "NOTICE" text file as part of its
+          distribution, then any Derivative Works that You distribute must
+          include a readable copy of the attribution notices contained
+          within such NOTICE file, excluding those notices that do not
+          pertain to any part of the Derivative Works, in at least one
+          of the following places: within a NOTICE text file distributed
+          as part of the Derivative Works; within the Source form or
+          documentation, if provided along with the Derivative Works; or,
+          within a display generated by the Derivative Works, if and
+          wherever such third-party notices normally appear. The contents
+          of the NOTICE file are for informational purposes only and
+          do not modify the License. You may add Your own attribution
+          notices within Derivative Works that You distribute, alongside
+          or as an addendum to the NOTICE text from the Work, provided
+          that such additional attribution notices cannot be construed
+          as modifying the License.
+
+      You may add Your own copyright statement to Your modifications and
+      may provide additional or different license terms and conditions
+      for use, reproduction, or distribution of Your modifications, or
+      for any such Derivative Works as a whole, provided Your use,
+      reproduction, and distribution of the Work otherwise complies with
+      the conditions stated in this License.
+
+   5. Submission of Contributions. Unless You explicitly state otherwise,
+      any Contribution intentionally submitted for inclusion in the Work
+      by You to the Licensor shall be under the terms and conditions of
+      this License, without any additional terms or conditions.
+      Notwithstanding the above, nothing herein shall supersede or modify
+      the terms of any separate license agreement you may have executed
+      with Licensor regarding such Contributions.
+
+   6. Trademarks. This License does not grant permission to use the trade
+      names, trademarks, service marks, or product names of the Licensor,
+      except as required for reasonable and customary use in describing the
+      origin of the Work and reproducing the content of the NOTICE file.
+
+   7. Disclaimer of Warranty. Unless required by applicable law or
+      agreed to in writing, Licensor provides the Work (and each
+      Contributor provides its Contributions) on an "AS IS" BASIS,
+      WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
+      implied, including, without limitation, any warranties or conditions
+      of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
+      PARTICULAR PURPOSE. You are solely responsible for determining the
+      appropriateness of using or redistributing the Work and assume any
+      risks associated with Your exercise of permissions under this License.
+
+   8. Limitation of Liability. In no event and under no legal theory,
+      whether in tort (including negligence), contract, or otherwise,
+      unless required by applicable law (such as deliberate and grossly
+      negligent acts) or agreed to in writing, shall any Contributor be
+      liable to You for damages, including any direct, indirect, special,
+      incidental, or consequential damages of any character arising as a
+      result of this License or out of the use or inability to use the
+      Work (including but not limited to damages for loss of goodwill,
+      work stoppage, computer failure or malfunction, or any and all
+      other commercial damages or losses), even if such Contributor
+      has been advised of the possibility of such damages.
+
+   9. Accepting Warranty or Additional Liability. While redistributing
+      the Work or Derivative Works thereof, You may choose to offer,
+      and charge a fee for, acceptance of support, warranty, indemnity,
+      or other liability obligations and/or rights consistent with this
+      License. However, in accepting such obligations, You may act only
+      on Your own behalf and on Your sole responsibility, not on behalf
+      of any other Contributor, and only if You agree to indemnify,
+      defend, and hold each Contributor harmless for any liability
+      incurred by, or claims asserted against, such Contributor by reason
+      of your accepting any such warranty or additional liability.
+
+   END OF TERMS AND CONDITIONS
+
+   APPENDIX: How to apply the Apache License to your work.
+
+      To apply the Apache License to your work, attach the following
+      boilerplate notice, with the fields enclosed by brackets "[]"
+      replaced with your own identifying information. (Don't include
+      the brackets!)  The text should be enclosed in the appropriate
+      comment syntax for the file format. We also recommend that a
+      file or class name and description of purpose be included on the
+      same "printed page" as the copyright notice for easier
+      identification within third-party archives.
+
+   Copyright [yyyy] [name of copyright owner]
+
+   Licensed under the Apache License, Version 2.0 (the "License");
+   you may not use this file except in compliance with the License.
+   You may obtain a copy of the License at
+
+       http://www.apache.org/licenses/LICENSE-2.0
+
+   Unless required by applicable law or agreed to in writing, software
+   distributed under the License is distributed on an "AS IS" BASIS,
+   WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+   See the License for the specific language governing permissions and
+   limitations under the License.
+
+
+

Added: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/NOTICE
URL: http://svn.apache.org/viewvc/tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/NOTICE?rev=1182320&view=auto
==============================================================================
--- tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/NOTICE (added)
+++ tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/NOTICE Wed Oct 12 11:58:27 2011
@@ -0,0 +1,6 @@
+${pom.name}
+Copyright (c) 2005 - 2011 The Apache Software Foundation
+
+This product includes software developed by
+The Apache Software Foundation (http://www.apache.org/).
+

Added: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/pom.xml
URL: http://svn.apache.org/viewvc/tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/pom.xml?rev=1182320&view=auto
==============================================================================
--- tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/pom.xml (added)
+++ tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/pom.xml Wed Oct 12 11:58:27 2011
@@ -0,0 +1,67 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!--
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ * 
+ *   http://www.apache.org/licenses/LICENSE-2.0
+ * 
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied.  See the License for the
+ * specific language governing permissions and limitations
+ * under the License.    
+-->
+<project>
+    <modelVersion>4.0.0</modelVersion>
+    <parent>
+        <groupId>org.apache.tuscany.sca</groupId>
+        <artifactId>tuscany-modules</artifactId>
+        <version>2.0-SNAPSHOT</version>
+        <relativePath>../pom.xml</relativePath>
+    </parent>
+    <artifactId>tuscany-policy-security-jsr250</artifactId>
+    <name>Apache Tuscany SCA Java JSR250 Implementation</name>
+
+    <dependencies>
+
+        <dependency>
+            <groupId>org.apache.tuscany.sca</groupId>
+            <artifactId>tuscany-core-runtime-pom</artifactId>
+            <version>2.0-SNAPSHOT</version>
+            <type>pom</type>
+            <scope>provided</scope>
+        </dependency>
+
+        <dependency>
+            <groupId>org.apache.tuscany.sca</groupId>
+            <artifactId>tuscany-implementation-java</artifactId>
+            <version>2.0-SNAPSHOT</version>
+        </dependency>
+        
+        <dependency>
+            <groupId>org.apache.tuscany.sca</groupId>
+            <artifactId>tuscany-policy-security</artifactId>
+            <version>2.0-SNAPSHOT</version>
+        </dependency>  
+        
+        <dependency>
+            <groupId>javax.annotation</groupId>
+            <artifactId>jsr250-api</artifactId>
+            <version>1.0</version>
+        </dependency>
+        
+        <dependency>
+            <groupId>org.apache.tuscany.sca</groupId>
+            <artifactId>tuscany-implementation-java-runtime</artifactId>
+            <version>2.0-SNAPSHOT</version>
+            <scope>test</scope>
+        </dependency>        
+    </dependencies>
+
+</project>

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/policy/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/policy/security/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/policy/security/jsr250/
------------------------------------------------------------------------------
    bugtraq:number = true

Added: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/policy/security/jsr250/JSR250PolicyProcessor.java
URL: http://svn.apache.org/viewvc/tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/policy/security/jsr250/JSR250PolicyProcessor.java?rev=1182320&view=auto
==============================================================================
--- tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/policy/security/jsr250/JSR250PolicyProcessor.java (added)
+++ tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/java/org/apache/tuscany/sca/policy/security/jsr250/JSR250PolicyProcessor.java Wed Oct 12 11:58:27 2011
@@ -0,0 +1,221 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *   http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied.  See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+package org.apache.tuscany.sca.policy.security.jsr250;
+
+import java.lang.reflect.Method;
+
+import javax.annotation.security.DenyAll;
+import javax.annotation.security.PermitAll;
+import javax.annotation.security.RolesAllowed;
+import javax.annotation.security.RunAs;
+import javax.xml.namespace.QName;
+
+import org.apache.tuscany.sca.assembly.AssemblyFactory;
+import org.apache.tuscany.sca.assembly.ConfiguredOperation;
+import org.apache.tuscany.sca.assembly.OperationsConfigurator;
+import org.apache.tuscany.sca.assembly.Service;
+import org.apache.tuscany.sca.assembly.xml.Constants;
+import org.apache.tuscany.sca.implementation.java.IntrospectionException;
+import org.apache.tuscany.sca.implementation.java.JavaImplementation;
+import org.apache.tuscany.sca.implementation.java.introspect.BaseJavaClassVisitor;
+import org.apache.tuscany.sca.interfacedef.Interface;
+import org.apache.tuscany.sca.interfacedef.Operation;
+import org.apache.tuscany.sca.interfacedef.java.JavaInterface;
+import org.apache.tuscany.sca.interfacedef.java.JavaOperation;
+import org.apache.tuscany.sca.policy.PolicyExpression;
+import org.apache.tuscany.sca.policy.PolicyFactory;
+import org.apache.tuscany.sca.policy.PolicySet;
+import org.apache.tuscany.sca.policy.PolicySubject;
+import org.apache.tuscany.sca.policy.authorization.AuthorizationPolicy;
+import org.apache.tuscany.sca.policy.identity.SecurityIdentityPolicy;
+
+/**
+ * Processes an {@link javax.annotation.security.*} annotation
+ * Below is a list of annotations
+ * 
+ *                Type    Method
+ * RunAs             x
+ * RolesAllowed      x       x
+ * PermitAll         x       x
+ * DenyAll                   x
+ *
+ */
+public class JSR250PolicyProcessor extends BaseJavaClassVisitor {
+    private static final QName RUN_AS = new QName(Constants.SCA11_TUSCANY_NS,"runAs");
+    private static final QName ALLOW = new QName(Constants.SCA11_TUSCANY_NS,"allow");
+    private static final QName PERMIT_ALL = new QName(Constants.SCA11_TUSCANY_NS,"permitAll");
+    private static final QName DENY_ALL = new QName(Constants.SCA11_TUSCANY_NS,"denyAll");
+    
+    private PolicyFactory policyFactory;
+
+    public JSR250PolicyProcessor(AssemblyFactory assemblyFactory, PolicyFactory policyFactory) {
+        super(assemblyFactory);
+        this.policyFactory = policyFactory;
+    }
+    
+
+    @Override
+    public <T> void visitClass(Class<T> clazz, JavaImplementation type) throws IntrospectionException {
+        
+        RunAs runAs = clazz.getAnnotation(javax.annotation.security.RunAs.class);
+        if (runAs != null) {
+            
+            String roleName = runAs.value();
+            if(roleName == null) {
+                //FIXME handle monitor or error
+            }
+
+            SecurityIdentityPolicy policy = new SecurityIdentityPolicy();
+            policy.setRunAsRole(roleName);
+
+            PolicySet policySet = policyFactory.createPolicySet();
+            policySet.setName(RUN_AS);
+            PolicyExpression policyExpression = policyFactory.createPolicyExpression();
+            policyExpression.setName(SecurityIdentityPolicy.NAME);
+            policyExpression.setPolicy(policy);
+            policySet.getPolicies().add(policyExpression);
+            policySet.setUnresolved(false);
+            type.getPolicySets().add(policySet);
+        }
+        
+        RolesAllowed rolesAllowed = clazz.getAnnotation(javax.annotation.security.RolesAllowed.class);
+        if(rolesAllowed != null) {
+            if(rolesAllowed.value().length == 0) {
+                //FIXME handle monitor or error
+            }
+            
+            AuthorizationPolicy policy = new AuthorizationPolicy();
+            policy.setAccessControl(AuthorizationPolicy.AcessControl.allow);
+            
+            for(String role : rolesAllowed.value()) {
+                policy.getRoleNames().add(role);
+            }
+
+            PolicySet policySet = policyFactory.createPolicySet();
+            policySet.setName(ALLOW);
+            PolicyExpression policyExpression = policyFactory.createPolicyExpression();
+            policyExpression.setName(AuthorizationPolicy.NAME);
+            policyExpression.setPolicy(policy);
+            policySet.getPolicies().add(policyExpression);
+            policySet.setUnresolved(false);
+            type.getPolicySets().add(policySet);
+        }
+        
+        PermitAll permitAll = clazz.getAnnotation(javax.annotation.security.PermitAll.class);
+        if(permitAll != null) {
+            AuthorizationPolicy policy = new AuthorizationPolicy();
+            policy.setAccessControl(AuthorizationPolicy.AcessControl.permitAll);
+            
+            PolicySet policySet = policyFactory.createPolicySet();
+            policySet.setName(PERMIT_ALL);
+            PolicyExpression policyExpression = policyFactory.createPolicyExpression();
+            policyExpression.setName(AuthorizationPolicy.NAME);
+            policyExpression.setPolicy(policy);
+            policySet.getPolicies().add(policyExpression);
+            policySet.setUnresolved(false);
+            type.getPolicySets().add(policySet);
+        }
+        
+    }
+    
+    @Override
+    public void visitMethod(Method method, JavaImplementation type) throws IntrospectionException {
+        RolesAllowed rolesAllowed = method.getAnnotation(javax.annotation.security.RolesAllowed.class);
+        if(rolesAllowed != null) {
+            if(rolesAllowed.value().length == 0) {
+                //FIXME handle monitor or error
+            }
+            
+            AuthorizationPolicy policy = new AuthorizationPolicy();
+            policy.setAccessControl(AuthorizationPolicy.AcessControl.allow);
+            
+            for(String role : rolesAllowed.value()) {
+                policy.getRoleNames().add(role);
+            }
+            
+            // find the operation in the interface model
+            Operation operation = getOperationModel(method, type);
+            
+            if (operation != null){
+                PolicySet policySet = policyFactory.createPolicySet();
+                policySet.setName(ALLOW);
+                PolicyExpression policyExpression = policyFactory.createPolicyExpression();
+                policyExpression.setName(AuthorizationPolicy.NAME);
+                policyExpression.setPolicy(policy);
+                policySet.getPolicies().add(policyExpression);
+                policySet.setUnresolved(false);
+                
+                operation.getPolicySets().add(policySet);
+            }
+        }
+        
+        PermitAll permitAll = method.getAnnotation(javax.annotation.security.PermitAll.class);
+        if(permitAll != null) {
+            AuthorizationPolicy policy = new AuthorizationPolicy();
+            policy.setAccessControl(AuthorizationPolicy.AcessControl.permitAll);
+            
+            // find the operation in the interface model
+            Operation operation = getOperationModel(method, type);
+            
+            if (operation != null){
+                PolicySet policySet = policyFactory.createPolicySet();
+                policySet.setName(PERMIT_ALL);
+                PolicyExpression policyExpression = policyFactory.createPolicyExpression();
+                policyExpression.setName(AuthorizationPolicy.NAME);
+                policyExpression.setPolicy(policy);
+                policySet.getPolicies().add(policyExpression);
+                policySet.setUnresolved(false);
+                
+                operation.getPolicySets().add(policySet);
+            }
+        }
+        
+        DenyAll denyAll = method.getAnnotation(javax.annotation.security.DenyAll.class);
+        if(denyAll != null) {
+            AuthorizationPolicy policy = new AuthorizationPolicy();
+            policy.setAccessControl(AuthorizationPolicy.AcessControl.denyAll);
+            
+            // find the operation in the interface model
+            Operation operation = getOperationModel(method, type);
+            
+            if (operation != null){
+                PolicySet policySet = policyFactory.createPolicySet();
+                policySet.setName(DENY_ALL);
+                PolicyExpression policyExpression = policyFactory.createPolicyExpression();
+                policyExpression.setName(AuthorizationPolicy.NAME);
+                policyExpression.setPolicy(policy);
+                policySet.getPolicies().add(policyExpression);
+                policySet.setUnresolved(false);
+                
+                operation.getPolicySets().add(policySet);
+            }
+        }
+    }  
+    
+    private Operation getOperationModel(Method method, JavaImplementation type){
+        
+        for(Operation op : type.getOperations()){
+            if (((JavaOperation)op).getJavaMethod().equals(method)){
+                return op;
+            } 
+        }
+        
+        return null;
+    }
+}

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/resources/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/resources/META-INF/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/resources/META-INF/services/
------------------------------------------------------------------------------
    bugtraq:number = true

Added: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/resources/META-INF/services/org.apache.tuscany.sca.implementation.java.introspect.JavaClassVisitor
URL: http://svn.apache.org/viewvc/tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/resources/META-INF/services/org.apache.tuscany.sca.implementation.java.introspect.JavaClassVisitor?rev=1182320&view=auto
==============================================================================
--- tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/resources/META-INF/services/org.apache.tuscany.sca.implementation.java.introspect.JavaClassVisitor (added)
+++ tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/main/resources/META-INF/services/org.apache.tuscany.sca.implementation.java.introspect.JavaClassVisitor Wed Oct 12 11:58:27 2011
@@ -0,0 +1,20 @@
+# Licensed to the Apache Software Foundation 
+# or more contributor license agreements.  See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership.  The ASF licenses this file
+# to you under the Apache License, Version 2.0 
+# "License"); you may not use this file except in compliance
+# with the License.  You may obtain a copy of the License at
+# 
+#   http://www.apache.org/licenses/LICENSE-2.0
+# 
+# Unless required by applicable law or agreed to in writing,
+# software distributed under the License is distributed on an
+# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+# KIND, either express or implied.  See the License for the
+# specific language governing permissions and limitations
+# under the License.
+# 
+# NOTE: The ranking attribute is important for the JavaClassVistors 
+# Some visitors need to be called after the others 
+org.apache.tuscany.sca.implementation.java.introspect.impl.JSR250PolicyProcessor;ranking=600
\ No newline at end of file

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/policy/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/policy/security/
------------------------------------------------------------------------------
    bugtraq:number = true

Propchange: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/policy/security/jsr250/
------------------------------------------------------------------------------
    bugtraq:number = true

Added: tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/policy/security/jsr250/PolicyProcessorTestCase.java
URL: http://svn.apache.org/viewvc/tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/policy/security/jsr250/PolicyProcessorTestCase.java?rev=1182320&view=auto
==============================================================================
--- tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/policy/security/jsr250/PolicyProcessorTestCase.java (added)
+++ tuscany/sca-java-2.x/trunk/modules/policy-security-jsr250/src/test/java/org/apache/tuscany/sca/policy/security/jsr250/PolicyProcessorTestCase.java Wed Oct 12 11:58:27 2011
@@ -0,0 +1,222 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *   http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied.  See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+package org.apache.tuscany.sca.policy.security.jsr250;
+
+import java.lang.reflect.Method;
+
+import javax.annotation.security.DenyAll;
+import javax.annotation.security.PermitAll;
+import javax.annotation.security.RolesAllowed;
+import javax.annotation.security.RunAs;
+
+import junit.framework.Assert;
+import junit.framework.TestCase;
+
+import org.apache.tuscany.sca.assembly.DefaultAssemblyFactory;
+import org.apache.tuscany.sca.core.DefaultExtensionPointRegistry;
+import org.apache.tuscany.sca.core.ExtensionPointRegistry;
+import org.apache.tuscany.sca.implementation.java.DefaultJavaImplementationFactory;
+import org.apache.tuscany.sca.implementation.java.JavaImplementation;
+import org.apache.tuscany.sca.implementation.java.JavaImplementationFactory;
+import org.apache.tuscany.sca.implementation.java.introspect.impl.PolicyProcessor;
+import org.apache.tuscany.sca.implementation.java.introspect.impl.ServiceProcessor;
+import org.apache.tuscany.sca.interfacedef.Operation;
+import org.apache.tuscany.sca.interfacedef.java.DefaultJavaInterfaceFactory;
+import org.apache.tuscany.sca.interfacedef.java.JavaInterface;
+import org.apache.tuscany.sca.interfacedef.java.JavaOperation;
+import org.apache.tuscany.sca.interfacedef.java.impl.PolicyJavaInterfaceVisitor;
+import org.apache.tuscany.sca.policy.DefaultPolicyFactory;
+import org.oasisopen.sca.annotation.Service;
+
+/**
+ * @version $Rev: 662474 $ $Date: 2008-06-02 17:18:28 +0100 (Mon, 02 Jun 2008) $
+ */
+public class PolicyProcessorTestCase extends TestCase {
+    private ExtensionPointRegistry registry;
+    private ServiceProcessor serviceProcessor;
+    private PolicyProcessor policyProcessor;
+    private JSR250PolicyProcessor jsr250Processor;
+    private PolicyJavaInterfaceVisitor visitor;
+    private JavaImplementation type;   
+    
+    private interface Interface1 {
+        int method1();
+
+        int method2();
+
+        int method3();
+
+        int method4();
+    }
+    
+    @RunAs("Role1")
+    @Service(Interface1.class)
+    private class Service1 implements Interface1 {
+        public int method1() {
+            return 0;
+        }
+
+        public int method2() {
+            return 0;
+        }
+
+        public int method3() {
+            return 0;
+        }
+
+        public int method4() {
+            return 0;
+        }
+    }   
+    
+    @RolesAllowed({"Role2", "Role3"})
+    @Service(Interface1.class)
+    private class Service2 implements Interface1 {
+        public int method1() {
+            return 0;
+        }
+
+        public int method2() {
+            return 0;
+        }
+
+        public int method3() {
+            return 0;
+        }
+
+        public int method4() {
+            return 0;
+        }
+    } 
+    
+    @PermitAll()
+    @Service(Interface1.class)
+    private class Service3 implements Interface1 {
+        public int method1() {
+            return 0;
+        }
+
+        public int method2() {
+            return 0;
+        }
+
+        public int method3() {
+            return 0;
+        }
+
+        public int method4() {
+            return 0;
+        }
+    }    
+    
+
+    @Service(Interface1.class)
+    private class Service4 implements Interface1 {
+        public int method1() {
+            return 0;
+        }
+
+        @RolesAllowed({"Role4", "Role5"})
+        public int method2() {
+            return 0;
+        }
+
+        @PermitAll
+        public int method3() {
+            return 0;
+        }
+
+        @DenyAll
+        public int method4() {
+            return 0;
+        }
+    }       
+    
+    @Override
+    protected void setUp() throws Exception {
+        super.setUp();
+        registry = new DefaultExtensionPointRegistry();
+        registry.start();
+        serviceProcessor = new ServiceProcessor(new DefaultAssemblyFactory(), new DefaultJavaInterfaceFactory(registry));
+        policyProcessor = new PolicyProcessor(registry);
+        jsr250Processor = new JSR250PolicyProcessor(new DefaultAssemblyFactory(), new DefaultPolicyFactory());
+        visitor = new PolicyJavaInterfaceVisitor(registry);
+        JavaImplementationFactory javaImplementationFactory = new DefaultJavaImplementationFactory();
+        type = javaImplementationFactory.createJavaImplementation();
+    }
+
+    public void testSingleInterfaceWithRunAsAtClassLevel() throws Exception {
+        runProcessors(Service1.class, null, type);
+        Assert.assertEquals(1, type.getPolicySets().size());
+    }  
+    
+    public void testSingleInterfaceWithRolesAllowedsAtClassLevel() throws Exception {
+        runProcessors(Service2.class, null, type);
+        Assert.assertEquals(1, type.getPolicySets().size());
+    }  
+    
+    public void testSingleInterfaceWithPermitAllAtClassLevel() throws Exception {
+        runProcessors(Service3.class, null, type);
+        Assert.assertEquals(1, type.getPolicySets().size());
+    }     
+    
+    public void testSingleInterfaceWithRolesAllowedAtMethodLevel() throws Exception {
+        runProcessors(Service4.class, Service4.class.getMethods()[1], type);
+        Operation op = getOperationModel(Service4.class.getMethods()[1], type);
+        Assert.assertEquals(1, op.getPolicySets().size());
+    } 
+    
+    public void testSingleInterfaceWithPermitAllAtMethodLevel() throws Exception {
+        runProcessors(Service4.class, Service4.class.getMethods()[2], type);
+        Operation op = getOperationModel(Service4.class.getMethods()[2], type);
+        Assert.assertEquals(1, op.getPolicySets().size());
+    }     
+
+    public void testSingleInterfaceWithDenyAllAtMethodLevel() throws Exception {
+        runProcessors(Service4.class, Service4.class.getMethods()[3], type);
+        Operation op = getOperationModel(Service4.class.getMethods()[3], type);
+        Assert.assertEquals(1, op.getPolicySets().size());
+    }  
+    
+    public void testSingleInterfaceWithNothingAtMethodLevel() throws Exception {
+        runProcessors(Service4.class, Service4.class.getMethods()[0], type);
+        Operation op = getOperationModel(Service4.class.getMethods()[0], type);
+        Assert.assertEquals(0, op.getPolicySets().size());
+    }      
+    
+    private void runProcessors(Class clazz, Method method, JavaImplementation type)throws Exception {
+        serviceProcessor.visitClass(clazz, type);
+        policyProcessor.visitClass(clazz, type);
+        jsr250Processor.visitClass(clazz, type);
+        if (method != null){
+            jsr250Processor.visitMethod(method, type);
+        }
+    }
+    
+    private Operation getOperationModel(Method method, JavaImplementation type){
+        
+        for(Operation op : type.getOperations()){
+            if (((JavaOperation)op).getJavaMethod().equals(method)){
+                return op;
+            } 
+        }
+        
+        return null;
+    }
+}