cn.eyes.commons.context; java.io.IOException; javax.servlet.ServletRequest; javax.servlet.ServletResponse; org.apache.shiro.subject.Subject; org.apache.shiro.web.filter.authz.AuthorizationFilter; AuthorizationFilter { isAccessAllowed(ServletRequest request, ServletResponse response, mappedValue) IOException { Subject subject getSubject(request, response); [] rolesArray ([]) mappedValue; (rolesArray rolesArray.length ) { ; } ( i;irolesArray.length;i){ (subject.hasRole(rolesArray[i])){ ; } } ; } }