Class BearerHttpAuthenticationFilter

java.lang.Object
All Implemented Interfaces:
javax.servlet.Filter, org.apache.shiro.lang.util.Nameable, PathConfigProcessor

Requires the requesting user to be authenticated for the request to continue, and if they're not, requires the user to login via the HTTP Bearer protocol-specific challenge. Upon successful login, they're allowed to continue on to the requested resource/url.

The AccessControlFilter.onAccessDenied(ServletRequest, ServletResponse) method will only be called if the subject making the request is not authenticated

Since:
1.5
See Also: