Annotation Type IsAuthorizedResourceOwnerOrAdmin
-
@Target(METHOD) @Retention(RUNTIME) @PreAuthorize("hasRole(\'TRUSTED_CLIENT\') OR @userValidator.isResourceOwner(authentication, #relatedPartyId)") public @interface IsAuthorizedResourceOwnerOrAdminAnnotation for securing rest endpoints.
Only users that have role TRUSTED_CLIENT or users that own the resource can retrieve data from this endpoint.- Since:
- 1907