jdk/src/share/classes/java/net/NetPermission.java
author xdono
Thu, 02 Oct 2008 19:58:32 -0700
changeset 1247 b4c26443dee5
parent 2 90ce3da70b43
child 5506 202f599c92aa
permissions -rw-r--r--
6754988: Update copyright year Summary: Update for files that have been modified starting July 2008 Reviewed-by: ohair, tbell
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
     1
/*
90ce3da70b43 Initial load
duke
parents:
diff changeset
     2
 * Copyright 1997-2004 Sun Microsystems, Inc.  All Rights Reserved.
90ce3da70b43 Initial load
duke
parents:
diff changeset
     3
 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
90ce3da70b43 Initial load
duke
parents:
diff changeset
     4
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
     5
 * This code is free software; you can redistribute it and/or modify it
90ce3da70b43 Initial load
duke
parents:
diff changeset
     6
 * under the terms of the GNU General Public License version 2 only, as
90ce3da70b43 Initial load
duke
parents:
diff changeset
     7
 * published by the Free Software Foundation.  Sun designates this
90ce3da70b43 Initial load
duke
parents:
diff changeset
     8
 * particular file as subject to the "Classpath" exception as provided
90ce3da70b43 Initial load
duke
parents:
diff changeset
     9
 * by Sun in the LICENSE file that accompanied this code.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    10
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    11
 * This code is distributed in the hope that it will be useful, but WITHOUT
90ce3da70b43 Initial load
duke
parents:
diff changeset
    12
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
90ce3da70b43 Initial load
duke
parents:
diff changeset
    13
 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
90ce3da70b43 Initial load
duke
parents:
diff changeset
    14
 * version 2 for more details (a copy is included in the LICENSE file that
90ce3da70b43 Initial load
duke
parents:
diff changeset
    15
 * accompanied this code).
90ce3da70b43 Initial load
duke
parents:
diff changeset
    16
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    17
 * You should have received a copy of the GNU General Public License version
90ce3da70b43 Initial load
duke
parents:
diff changeset
    18
 * 2 along with this work; if not, write to the Free Software Foundation,
90ce3da70b43 Initial load
duke
parents:
diff changeset
    19
 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    20
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    21
 * Please contact Sun Microsystems, Inc., 4150 Network Circle, Santa Clara,
90ce3da70b43 Initial load
duke
parents:
diff changeset
    22
 * CA 95054 USA or visit www.sun.com if you need additional information or
90ce3da70b43 Initial load
duke
parents:
diff changeset
    23
 * have any questions.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    24
 */
90ce3da70b43 Initial load
duke
parents:
diff changeset
    25
90ce3da70b43 Initial load
duke
parents:
diff changeset
    26
package java.net;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    27
90ce3da70b43 Initial load
duke
parents:
diff changeset
    28
import java.security.*;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    29
import java.util.Enumeration;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    30
import java.util.Hashtable;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    31
import java.util.StringTokenizer;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    32
90ce3da70b43 Initial load
duke
parents:
diff changeset
    33
/**
90ce3da70b43 Initial load
duke
parents:
diff changeset
    34
 * This class is for various network permissions.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    35
 * A NetPermission contains a name (also referred to as a "target name") but
90ce3da70b43 Initial load
duke
parents:
diff changeset
    36
 * no actions list; you either have the named permission
90ce3da70b43 Initial load
duke
parents:
diff changeset
    37
 * or you don't.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    38
 * <P>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    39
 * The target name is the name of the network permission (see below). The naming
90ce3da70b43 Initial load
duke
parents:
diff changeset
    40
 * convention follows the  hierarchical property naming convention.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    41
 * Also, an asterisk
90ce3da70b43 Initial load
duke
parents:
diff changeset
    42
 * may appear at the end of the name, following a ".", or by itself, to
90ce3da70b43 Initial load
duke
parents:
diff changeset
    43
 * signify a wildcard match. For example: "foo.*" or "*" is valid,
90ce3da70b43 Initial load
duke
parents:
diff changeset
    44
 * "*foo" or "a*b" is not valid.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    45
 * <P>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    46
 * The following table lists all the possible NetPermission target names,
90ce3da70b43 Initial load
duke
parents:
diff changeset
    47
 * and for each provides a description of what the permission allows
90ce3da70b43 Initial load
duke
parents:
diff changeset
    48
 * and a discussion of the risks of granting code the permission.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    49
 * <P>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    50
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    51
 * <table border=1 cellpadding=5 summary="Permission target name, what the permission allows, and associated risks">
90ce3da70b43 Initial load
duke
parents:
diff changeset
    52
 * <tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    53
 * <th>Permission Target Name</th>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    54
 * <th>What the Permission Allows</th>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    55
 * <th>Risks of Allowing this Permission</th>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    56
 * </tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    57
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    58
 * <tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    59
 *   <td>setDefaultAuthenticator</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    60
 *   <td>The ability to set the
90ce3da70b43 Initial load
duke
parents:
diff changeset
    61
 * way authentication information is retrieved when
90ce3da70b43 Initial load
duke
parents:
diff changeset
    62
 * a proxy or HTTP server asks for authentication</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    63
 *   <td>Malicious
90ce3da70b43 Initial load
duke
parents:
diff changeset
    64
 * code can set an authenticator that monitors and steals user
90ce3da70b43 Initial load
duke
parents:
diff changeset
    65
 * authentication input as it retrieves the input from the user.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    66
 * </tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    67
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    68
 * <tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    69
 *   <td>requestPasswordAuthentication</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    70
 *   <td>The ability
90ce3da70b43 Initial load
duke
parents:
diff changeset
    71
 * to ask the authenticator registered with the system for
90ce3da70b43 Initial load
duke
parents:
diff changeset
    72
 * a password</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    73
 *   <td>Malicious code may steal this password.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    74
 * </tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    75
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    76
 * <tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    77
 *   <td>specifyStreamHandler</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    78
 *   <td>The ability
90ce3da70b43 Initial load
duke
parents:
diff changeset
    79
 * to specify a stream handler when constructing a URL</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    80
 *   <td>Malicious code may create a URL with resources that it would
90ce3da70b43 Initial load
duke
parents:
diff changeset
    81
normally not have access to (like file:/foo/fum/), specifying a
90ce3da70b43 Initial load
duke
parents:
diff changeset
    82
stream handler that gets the actual bytes from someplace it does
90ce3da70b43 Initial load
duke
parents:
diff changeset
    83
have access to. Thus it might be able to trick the system into
90ce3da70b43 Initial load
duke
parents:
diff changeset
    84
creating a ProtectionDomain/CodeSource for a class even though
90ce3da70b43 Initial load
duke
parents:
diff changeset
    85
that class really didn't come from that location.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    86
 * </tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    87
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    88
 * <tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    89
 *   <td>setProxySelector</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    90
 *   <td>The ability to set the proxy selector used to make decisions
90ce3da70b43 Initial load
duke
parents:
diff changeset
    91
 *   on which proxies to use when making network connections.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    92
 *   <td>Malicious code can set a ProxySelector that directs network
90ce3da70b43 Initial load
duke
parents:
diff changeset
    93
 *   traffic to an arbitrary network host.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    94
 * </tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    95
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    96
 * <tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    97
 *   <td>getProxySelector</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
    98
 *   <td>The ability to get the proxy selector used to make decisions
90ce3da70b43 Initial load
duke
parents:
diff changeset
    99
 *   on which proxies to use when making network connections.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   100
 *   <td>Malicious code can get a ProxySelector to discover proxy
90ce3da70b43 Initial load
duke
parents:
diff changeset
   101
 *   hosts and ports on internal networks, which could then become
90ce3da70b43 Initial load
duke
parents:
diff changeset
   102
 *   targets for attack.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   103
 * </tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   104
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   105
 * <tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   106
 *   <td>setCookieHandler</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   107
 *   <td>The ability to set the cookie handler that processes highly
90ce3da70b43 Initial load
duke
parents:
diff changeset
   108
 *   security sensitive cookie information for an Http session.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   109
 *   <td>Malicious code can set a cookie handler to obtain access to
90ce3da70b43 Initial load
duke
parents:
diff changeset
   110
 *   highly security sensitive cookie information. Some web servers
90ce3da70b43 Initial load
duke
parents:
diff changeset
   111
 *   use cookies to save user private information such as access
90ce3da70b43 Initial load
duke
parents:
diff changeset
   112
 *   control information, or to track user browsing habit.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   113
 *   </tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   114
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   115
 * <tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   116
 *   <td>getCookieHandler</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   117
 *   <td>The ability to get the cookie handler that processes highly
90ce3da70b43 Initial load
duke
parents:
diff changeset
   118
 *   security sensitive cookie information for an Http session.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   119
 *   <td>Malicious code can get a cookie handler to obtain access to
90ce3da70b43 Initial load
duke
parents:
diff changeset
   120
 *   highly security sensitive cookie information. Some web servers
90ce3da70b43 Initial load
duke
parents:
diff changeset
   121
 *   use cookies to save user private information such as access
90ce3da70b43 Initial load
duke
parents:
diff changeset
   122
 *   control information, or to track user browsing habit.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   123
 *   </tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   124
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   125
 * <tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   126
 *   <td>setResponseCache</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   127
 *   <td>The ability to set the response cache that provides access to
90ce3da70b43 Initial load
duke
parents:
diff changeset
   128
 *   a local response cache.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   129
 *   <td>Malicious code getting access to the local response cache
90ce3da70b43 Initial load
duke
parents:
diff changeset
   130
 *   could access security sensitive information, or create false
90ce3da70b43 Initial load
duke
parents:
diff changeset
   131
 *   entries in the response cache.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   132
 *   </tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   133
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   134
 * <tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   135
 *   <td>getResponseCache</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   136
 *   <td>The ability to get the response cache that provides
90ce3da70b43 Initial load
duke
parents:
diff changeset
   137
 *   access to a local response cache.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   138
 *   <td>Malicious code getting access to the local response cache
90ce3da70b43 Initial load
duke
parents:
diff changeset
   139
 *   could access security sensitive information.</td>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   140
 *   </tr>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   141
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   142
 * </table>
90ce3da70b43 Initial load
duke
parents:
diff changeset
   143
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   144
 * @see java.security.BasicPermission
90ce3da70b43 Initial load
duke
parents:
diff changeset
   145
 * @see java.security.Permission
90ce3da70b43 Initial load
duke
parents:
diff changeset
   146
 * @see java.security.Permissions
90ce3da70b43 Initial load
duke
parents:
diff changeset
   147
 * @see java.security.PermissionCollection
90ce3da70b43 Initial load
duke
parents:
diff changeset
   148
 * @see java.lang.SecurityManager
90ce3da70b43 Initial load
duke
parents:
diff changeset
   149
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   150
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   151
 * @author Marianne Mueller
90ce3da70b43 Initial load
duke
parents:
diff changeset
   152
 * @author Roland Schemers
90ce3da70b43 Initial load
duke
parents:
diff changeset
   153
 */
90ce3da70b43 Initial load
duke
parents:
diff changeset
   154
90ce3da70b43 Initial load
duke
parents:
diff changeset
   155
public final class NetPermission extends BasicPermission {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   156
    private static final long serialVersionUID = -8343910153355041693L;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   157
90ce3da70b43 Initial load
duke
parents:
diff changeset
   158
    /**
90ce3da70b43 Initial load
duke
parents:
diff changeset
   159
     * Creates a new NetPermission with the specified name.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   160
     * The name is the symbolic name of the NetPermission, such as
90ce3da70b43 Initial load
duke
parents:
diff changeset
   161
     * "setDefaultAuthenticator", etc. An asterisk
90ce3da70b43 Initial load
duke
parents:
diff changeset
   162
     * may appear at the end of the name, following a ".", or by itself, to
90ce3da70b43 Initial load
duke
parents:
diff changeset
   163
     * signify a wildcard match.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   164
     *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   165
     * @param name the name of the NetPermission.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   166
     *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   167
     * @throws NullPointerException if <code>name</code> is <code>null</code>.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   168
     * @throws IllegalArgumentException if <code>name</code> is empty.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   169
     */
90ce3da70b43 Initial load
duke
parents:
diff changeset
   170
90ce3da70b43 Initial load
duke
parents:
diff changeset
   171
    public NetPermission(String name)
90ce3da70b43 Initial load
duke
parents:
diff changeset
   172
    {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   173
        super(name);
90ce3da70b43 Initial load
duke
parents:
diff changeset
   174
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   175
90ce3da70b43 Initial load
duke
parents:
diff changeset
   176
    /**
90ce3da70b43 Initial load
duke
parents:
diff changeset
   177
     * Creates a new NetPermission object with the specified name.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   178
     * The name is the symbolic name of the NetPermission, and the
90ce3da70b43 Initial load
duke
parents:
diff changeset
   179
     * actions String is currently unused and should be null.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   180
     *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   181
     * @param name the name of the NetPermission.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   182
     * @param actions should be null.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   183
     *
90ce3da70b43 Initial load
duke
parents:
diff changeset
   184
     * @throws NullPointerException if <code>name</code> is <code>null</code>.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   185
     * @throws IllegalArgumentException if <code>name</code> is empty.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   186
     */
90ce3da70b43 Initial load
duke
parents:
diff changeset
   187
90ce3da70b43 Initial load
duke
parents:
diff changeset
   188
    public NetPermission(String name, String actions)
90ce3da70b43 Initial load
duke
parents:
diff changeset
   189
    {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   190
        super(name, actions);
90ce3da70b43 Initial load
duke
parents:
diff changeset
   191
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   192
}