Class ToolPermissions

java.lang.Object
io.jenkins.plugins.mcp.server.tool.ToolPermissions

public final class ToolPermissions extends Object
Turns @Tool(permissions = ...) ids into Permissions and checks them against a caller.
  • Method Details

    • resolve

      public static List<Permission> resolve(@Nullable String[] ids)
      Resolves permission ids to Permissions. An unknown id throws right away, so a typo in a @Tool is caught at startup instead of quietly letting everyone through.
    • isAllowed

      public static boolean isAllowed(@Nullable org.springframework.security.core.Authentication auth, Collection<Permission> required)
      Whether auth may use a tool requiring required. No requirement, or security off, means yes; otherwise the user needs at least one of them. Checked against the Jenkins root, so overall permissions only - not item-level ones.