Hi been working on a grails 6 upgrade and have ran...
# questions
d
Hi been working on a grails 6 upgrade and have ran into issues due to the grails.plugins:spring-security-acl plugin no longer working meaning we can't make use of preauthorise functions in services. Is anyone aware of ways to get around this issue other than just moving all the auth checks into the service functions.
p
I understand the challenge you are facing with the
grails.plugins;spring-security-acl
plugin not working in Grails 6. Unfortunately, with the plugin not being updated to support Grails 6, you're left with a few options. To better assist you, could you provide more details on the specific issues you're encountering with the plugin? Knowing exactly what's breaking might help suggest more targeted solutions. That said, here are some potential paths forward: 1. Direct Use of Spring Security: You could shift to using Spring Security's native annotations (
@PreAuthorize
,
@Secured
, etc.) within your services and controllers. This approach may involve restructuring how you perform authorization but could provide a cleaner and more manageable solution. 2. Custom Authorization Layer: If you want to avoid scattering authorization logic throughout your services, consider abstracting it into reusable components or methods that encapsulate your access control logic. This way, your service functions remain uncluttered, and authorization is centralized. 3. Migrating to Native Spring Security ACL: While it might require some refactoring, you could move away from the Grails-specific ACL plugin and leverage Spring Security's native ACL features. This would future-proof your application by aligning with Spring's ongoing development. 4. Help Fix the Plugin: If you are open to it, another option another option is to contribute towards fixing the plugin to support Grails 6. I can assist with this effort and help you get the updated version released quickly, minimize disruption of your application. 5. Paid Consulting Services: If you're looking for more in-depth assistance, I also offer paid services to help guide you through finding the best path for your Grails 6 upgrade. Whether it's fixing the plugin, migrating your security architecture, or general Grails upgrade support, we can work together to get you up and running smoothly. Feel free to reach out if any of these options resonate with you! Best regards, Puneet
d
Thank you for the detailed response. I ended up going with basically your option 2 which i found to be quite straightforward and having a few services to cover the auth logic. I would love to spend some time getting the plugin but on its feet but time constraints meant that was not currently an option.
👍 1
p
I'm glad to hear that option #2 worked out well for you! It's a solid approach for keeping the auth logic modular and maintainable across your services. I completely understand the time constraints. When you do get the bandwidth to revisit the plugin, feel free to reach out - I'd be happy to help to get it back on its feet and work with you to release an updated version for Grails 6. In the meantime, if you run into any further challenges or need help down the road, don't hesitate to get in touch!
🙌 1