Over a million developers have joined DZone.
{{announcement.body}}
{{announcement.title}}

Reflection and the Missing Security Manager

DZone's Guide to

Reflection and the Missing Security Manager

· Java Zone ·
Free Resource

Verify, standardize, and correct the Big 4 + more– name, email, phone and global addresses – try our Data Quality APIs now at Melissa Developer Portal!

Here's an interesting trick that's been around for a long time:

Consider the Person class here, with password as a private data member.

public class Person {

private String name;
private String password;

public String getName() {
return name;
}

public boolean login(String password) {
if(this.password(equals(password)) {
....
}
}
...
}

The Java scope rules do not allow me to access or modify the password field that's declared private. All the same, I could do it using reflection as shown below:

   Person person = db.queryPerson("alosh");
//System.out.println("password: "+person.password); -- won't compile

Field field = person.getClass().getField("password");
field.setAccessible(true);
System.out.println("password: "+field.get(person));
field.set(person, "welcome");
person.login("welcome");
...

It all boils down to this line of code.

   field.setAccessible(true);

All reflection access to an object (methods, fields, constructors) is through the interface AccessibleObject which lets the reflected object suppress the normal access controls. By setting the access flag, the reflected object is now open. But the access flags are not flipped before it checks with the security manager. Reflection and SecurityManager together provides the power to control access dynamically. Our little trick could then be attributed to the SecurityManager. Or like in this case, the lack of a SecurityManager. By default the JVM does not have a SecurityManager available. A security manager could be installed either by passing the following option to the jvm

-Djava.security.manager
or by setting one in the code
System.setSecurityManager(new SecurityManager());

(Now the snippet mentioned in the beginning will not work.)

     * SecurityManager is not enabled by default in the JVM.

     * Majority of the JEE servers out there don't run a SecurityManager unless asked for.

     * Many applications would not run with SecurityManager in place.

Isn't it against Java's principle of 'Secure by Default'?

From http://www.aloshbennett.in/weblog/2010/java/reflection-and-the-missing-security-manager/

Developers! Quickly and easily gain access to the tools and information you need! Explore, test and combine our data quality APIs at Melissa Developer Portal – home to tools that save time and boost revenue. Our APIs verify, standardize, and correct the Big 4 + more – name, email, phone and global addresses – to ensure accurate delivery, prevent blacklisting and identify risks in real-time.

Topics:

Opinions expressed by DZone contributors are their own.

{{ parent.title || parent.header.title}}

{{ parent.tldr }}

{{ parent.urlSource.name }}