I want to use Spring Security to manage user, group and permissions.
I want to use ACL to secure my domain objects but I can\'t find a way to assign a group to an acl.>
Check Spring Security 3.0, you might be able to avoid using ACL at all by using the Spring Expression Language.
For instance, for editing a forum, you would have a method secured like this:
@PreAuthorize("hasRole('ROLE_FORUM_MANAGER') and hasPermission(#forum,'update'))
public void updateForum(Forum forum) {
//some implementation
You would then implement the hasPermission method in a custom permission evaluator, like:
public class ForumPermissionEvaluator implements PermissionEvaluator {
public boolean hasPermission(Authentication authentication,
Object domainObject, Object permission) {
public boolean hasPermission(Authentication authentication,
Serializable targetId, String targetType, Object permission) {
Finally, wire it up together in the application config: