src/share/jaxws_classes/javax/xml/bind/JAXBPermission.java

Tue, 09 Apr 2013 14:51:13 +0100

author
alanb
date
Tue, 09 Apr 2013 14:51:13 +0100
changeset 368
0989ad8c0860
parent 286
f50545b5e2f1
child 397
b99d7e355d4b
permissions
-rw-r--r--

8010393: Update JAX-WS RI to 2.2.9-b12941
Reviewed-by: alanb, erikj
Contributed-by: miroslav.kos@oracle.com, martin.grebac@oracle.com

ohair@286 1 /*
ohair@286 2 * Copyright (c) 2007, 2010, Oracle and/or its affiliates. All rights reserved.
ohair@286 3 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
ohair@286 4 *
ohair@286 5 * This code is free software; you can redistribute it and/or modify it
ohair@286 6 * under the terms of the GNU General Public License version 2 only, as
ohair@286 7 * published by the Free Software Foundation. Oracle designates this
ohair@286 8 * particular file as subject to the "Classpath" exception as provided
ohair@286 9 * by Oracle in the LICENSE file that accompanied this code.
ohair@286 10 *
ohair@286 11 * This code is distributed in the hope that it will be useful, but WITHOUT
ohair@286 12 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
ohair@286 13 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
ohair@286 14 * version 2 for more details (a copy is included in the LICENSE file that
ohair@286 15 * accompanied this code).
ohair@286 16 *
ohair@286 17 * You should have received a copy of the GNU General Public License version
ohair@286 18 * 2 along with this work; if not, write to the Free Software Foundation,
ohair@286 19 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
ohair@286 20 *
ohair@286 21 * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
ohair@286 22 * or visit www.oracle.com if you need additional information or have any
ohair@286 23 * questions.
ohair@286 24 */
ohair@286 25
ohair@286 26 package javax.xml.bind;
ohair@286 27
ohair@286 28 import java.security.BasicPermission;
ohair@286 29
ohair@286 30 /**
ohair@286 31 * This class is for JAXB permissions. A {@code JAXBPermission}
ohair@286 32 * contains a name (also referred to as a "target name") but
ohair@286 33 * no actions list; you either have the named permission
ohair@286 34 * or you don't.
ohair@286 35 *
ohair@286 36 * <P>
ohair@286 37 * The target name is the name of the JAXB permission (see below).
ohair@286 38 *
ohair@286 39 * <P>
ohair@286 40 * The following table lists all the possible {@code JAXBPermission} target names,
ohair@286 41 * and for each provides a description of what the permission allows
ohair@286 42 * and a discussion of the risks of granting code the permission.
ohair@286 43 * <P>
ohair@286 44 *
ohair@286 45 * <table border=1 cellpadding=5 summary="Permission target name, what the permission allows, and associated risks">
ohair@286 46 * <tr>
ohair@286 47 * <th>Permission Target Name</th>
ohair@286 48 * <th>What the Permission Allows</th>
ohair@286 49 * <th>Risks of Allowing this Permission</th>
ohair@286 50 * </tr>
ohair@286 51 *
ohair@286 52 * <tr>
ohair@286 53 * <td>setDatatypeConverter</td>
ohair@286 54 * <td>
ohair@286 55 * Allows the code to set VM-wide {@link DatatypeConverterInterface}
ohair@286 56 * via {@link DatatypeConverter#setDatatypeConverter(DatatypeConverterInterface) the setDatatypeConverter method}
ohair@286 57 * that all the methods on {@link DatatypeConverter} uses.
ohair@286 58 * </td>
ohair@286 59 * <td>
ohair@286 60 * Malicious code can set {@link DatatypeConverterInterface}, which has
ohair@286 61 * VM-wide singleton semantics, before a genuine JAXB implementation sets one.
ohair@286 62 * This allows malicious code to gain access to objects that it may otherwise
alanb@368 63 * not have access to, such as {@link java.awt.Frame#getFrames()} that belongs to
ohair@286 64 * another application running in the same JVM.
ohair@286 65 * </td>
ohair@286 66 * </tr>
ohair@286 67 * </table>
ohair@286 68 *
ohair@286 69 * @see java.security.BasicPermission
ohair@286 70 * @see java.security.Permission
ohair@286 71 * @see java.security.Permissions
ohair@286 72 * @see java.security.PermissionCollection
ohair@286 73 * @see java.lang.SecurityManager
ohair@286 74 *
ohair@286 75 * @author Joe Fialli
ohair@286 76 * @since JAXB 2.2
ohair@286 77 */
ohair@286 78
ohair@286 79 /* code was borrowed originally from java.lang.RuntimePermission. */
ohair@286 80 public final class JAXBPermission extends BasicPermission {
ohair@286 81 /**
ohair@286 82 * Creates a new JAXBPermission with the specified name.
ohair@286 83 *
ohair@286 84 * @param name
ohair@286 85 * The name of the JAXBPermission. As of 2.2 only "setDatatypeConverter"
ohair@286 86 * is defined.
ohair@286 87 */
ohair@286 88 public JAXBPermission(String name) {
ohair@286 89 super(name);
ohair@286 90 }
ohair@286 91
ohair@286 92 private static final long serialVersionUID = 1L;
ohair@286 93 }

mercurial