> Markdown version of [Accessing Auth Data](https://vaadin.com/docs/next/hilla/guides/security/authentication). Section index: [llms.txt](https://vaadin.com/docs/next/hilla/llms.txt)

# Accessing Authentication Data

Although authorization is defined at service level (as described in the [Security page](https://vaadin.com/docs/next/hilla/guides/security/configuring.md)), you may need to know specific authentication parameters, either in the Java service code or in client-side code.

Accessing authentication data such as username and roles on the server side, as well as transferring the data to the client, is explained here.

## <a id="server-side-access"></a>Server Side Access

### <a id="security-principal"></a>Security Principal

Hilla authenticates each server request and, if authentication is successful, associates the request with a Java security principal. You can get the authenticated user as a `UserPrincipal` from the current request. You can retrieve the current request using `VaadinRequest.getCurrent()`. Calling `getUserPrincipal()` for the request returns the authenticated user, or null if the request isn’t authenticated.

`EchoService.java`

```java
@BrowserCallable
public class EchoService {
    @PermitAll
    public String saySomething(String message) {
        return VaadinRequest.getCurrent().getUserPrincipal().getName() + " says: " + message;
    }
}
```

`frontend/index.ts`

```typescript
import { EchoService } from 'Frontend/generated/EchoService';

EchoService
    .saySomething("It's snowing in Turku")
    .then(response => console.log(response));
```

## <a id="client-side-authentication"></a>Client Side Authentication

### <a id="checking-the-username"></a>Checking the Username

In TypeScript, there is no direct way to check whether the user is authenticated. However, you can expose a server-side service method that checks user privileges and returns the status.

The next example returns the username if the user is logged in; otherwise it returns the word `anonymousUser`:

```java
import org.springframework.security.core.Authentication;
import org.springframework.security.core.context.SecurityContextHolder;

@BrowserCallable
public class MyAppService {

    @AnonymousAllowed
    public String checkUser() {
        Authentication auth =
            SecurityContextHolder.getContext().getAuthentication();
        return auth == null ? null : auth.getName();
    }
}
```

```typescript
import { MyAppService } from 'Frontend/generated/MyAppService';

const username = await MyAppService.checkUser();

if ('anonymousUser' === username) {
   console.log('You are an anonymous user');
} else {
   console.log('Your username is: ' + username);
}
```

### <a id="checking-roles"></a>Checking Roles

A developer might want to check whether the user can access certain services, so that the appropriate options are enabled in the application menu.

The following example exposes a method that checks whether a user is an admin user.

```java
@BrowserCallable
public class MyAppService {

    @RolesAllowed("ROLE_ADMIN")
    public boolean isAdmin() {
        return true;
    }
}
```

```typescript
import { MyAppService } from 'Frontend/generated/MyAppService';

const isAdmin = await MyAppService.isAdmin().catch(() => false);

if (isAdmin) {
   console.log('You are an admin user');
} else {
   console.log('Sorry, you are not an admin user');
}
```
