Annotation Type IsAuthorizedResourceOwnerOrAdmin


  • @Target(METHOD)
    @Retention(RUNTIME)
    @PreAuthorize("hasRole(\'TRUSTED_CLIENT\') OR @userValidator.isResourceOwner(authentication, #relatedPartyId)")
    public @interface IsAuthorizedResourceOwnerOrAdmin
    Annotation for securing rest endpoints.
    Only users that have role TRUSTED_CLIENT or users that own the resource can retrieve data from this endpoint.
    Since:
    1907