Give groovy scripts read access to groovy.indy.logging, needed for

IndyInterface bootstrap.
This commit is contained in:
Robert Muir 2015-09-15 12:00:49 -04:00 committed by Chris Earle
parent 6a779fc730
commit 7828460ef6
1 changed files with 8 additions and 2 deletions

View File

@ -26,9 +26,11 @@ import java.net.URL;
import java.security.CodeSource; import java.security.CodeSource;
import java.security.Permission; import java.security.Permission;
import java.security.PermissionCollection; import java.security.PermissionCollection;
import java.security.Permissions;
import java.security.Policy; import java.security.Policy;
import java.security.ProtectionDomain; import java.security.ProtectionDomain;
import java.security.URIParameter; import java.security.URIParameter;
import java.util.PropertyPermission;
/** custom policy for union of static and dynamic permissions */ /** custom policy for union of static and dynamic permissions */
final class ESPolicy extends Policy { final class ESPolicy extends Policy {
@ -38,11 +40,15 @@ final class ESPolicy extends Policy {
final Policy template; final Policy template;
final PermissionCollection dynamic; final PermissionCollection dynamic;
final PermissionCollection groovy;
public ESPolicy(PermissionCollection dynamic) throws Exception { public ESPolicy(PermissionCollection dynamic) throws Exception {
URI uri = getClass().getResource(POLICY_RESOURCE).toURI(); URI uri = getClass().getResource(POLICY_RESOURCE).toURI();
this.template = Policy.getInstance("JavaPolicy", new URIParameter(uri)); this.template = Policy.getInstance("JavaPolicy", new URIParameter(uri));
this.dynamic = dynamic; this.dynamic = dynamic;
this.groovy = new Permissions();
// groovy IndyInterface bootstrap requires this property
groovy.add(new PropertyPermission("groovy.indy.logging", "read"));
} }
@Override @SuppressForbidden(reason = "fast equals check is desired") @Override @SuppressForbidden(reason = "fast equals check is desired")
@ -54,9 +60,9 @@ final class ESPolicy extends Policy {
// location can be null... ??? nobody knows // location can be null... ??? nobody knows
// https://bugs.openjdk.java.net/browse/JDK-8129972 // https://bugs.openjdk.java.net/browse/JDK-8129972
if (location != null) { if (location != null) {
// run groovy scripts with no permissions // run groovy scripts with no permissions (except logging property)
if ("/groovy/script".equals(location.getFile())) { if ("/groovy/script".equals(location.getFile())) {
return false; return groovy.implies(permission);
} }
} }
} }