diff --git a/docs/modules/ROOT/pages/servlet/authorization/method-security.adoc b/docs/modules/ROOT/pages/servlet/authorization/method-security.adoc index 51949ca534..089b14ae2a 100644 --- a/docs/modules/ROOT/pages/servlet/authorization/method-security.adoc +++ b/docs/modules/ROOT/pages/servlet/authorization/method-security.adoc @@ -369,7 +369,7 @@ fun readAccountWithWrongRoleThenAccessDenied() { `@PreAuthorize` also can be a <>, be defined <>, and use <>. While `@PreAuthorize` is quite helpful for declaring needed authorities, it can also be used to evaluate more complex <>. -asdf + The above two snippets are ensuring that the user can only request orders that belong to them by comparing the username parameter to xref:servlet/authentication/architecture.adoc#servlet-authentication-authentication[`Authentication#getName`]. The result is that the above method will only be invoked if the `username` in the request path matches the logged-in user's `name`.