You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ADF中使用Groovy表达式获取securityContext属性报错如何解决

ADF Groovy调用securityContext权限报错解决方案

错误信息:
Exception in expression "dCode" bound parameter value expression : oracle.jbo.script.ExprSecurityException Accessing the sessionScope property on class oracle.adf.share.http.ServletADFContext is not permitted.
at "dCode" BoundParameter line 1

可行解决方案

  • 优先更换授权的表达式写法
    原写法adf.context.securityContext.get('dCode')触发了ADF脚本的会话属性访问校验,直接替换为官方允许的userAttribute方法调用即可:
    adf.context.securityContext.userAttribute('dCode')

  • 配置表达式访问白名单(ADF 12c+适用)
    打开应用的adf-config.xml,新增/修改adf-scripting-config节点配置,放开securityContext的访问权限:

    <adf-scripting-config xmlns="http://xmlns.oracle.com/adf/scripting/config">
      <expression-security>
        <allowed-classes>
          <class-name>oracle.adf.share.security.SecurityContext</class-name>
        </allowed-classes>
        <allowed-properties>
          <property>
            <class-name>oracle.adf.share.http.ServletADFContext</class-name>
            <property-name>securityContext</property-name>
          </property>
        </allowed-properties>
      </expression-security>
    </adf-scripting-config>
    

    配置完成后重启应用生效。

  • 托管Bean中转获取
    针对权限管控严格的场景,可通过Java Bean中转获取值绕过脚本校验:

    1. 新建请求作用域托管Bean,添加获取方法:
      import oracle.adf.share.ADFContext;
      
      public class SecurityAttrBean {
          public String getDCode() {
              return (String) ADFContext.getCurrent().getSecurityContext().getUserAttribute("dCode");
          }
      }
      
    2. Groovy表达式直接调用Bean属性即可:#{securityAttrBean.dCode}
  • 补丁版本校验(ADF 11g R2适用)
    部分旧版本ADF存在脚本权限校验误判bug,升级到对应版本的最新补丁集即可修复该问题。


内容的提问来源于stack exchange,提问作者Ali

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.28 12:54:04