Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Java EnumSet complementOf: derive a default-deny capability set

Last updated: 5 Oct 20265 min read
tutorial
AdvancedBy AITrove Editorial

EnumSet.complementOf returns a new set containing enum constants absent from the supplied EnumSet. Its universe is the entire enum type, not just constants known to one caller.

Operational contract

The helper constructs a fresh denied set from an allowed capability set. Adding a new enum constant automatically puts it in denied until the policy explicitly allows it, which is appropriate for this default-deny design. The result is a separate mutable EnumSet; changing allowed later does not update the previous result. If a product instead interprets the complement as granted permissions, a newly introduced constant could become granted accidentally. The allowed set itself still requires an authorization source and review.

Failure case

A release adds ARCHIVE. Existing callers allow only READ and EXPORT. The computed denied set includes ARCHIVE without changing the callers' allowlists.

Java code

Java
import java.util.EnumSet;
import java.util.Objects;

public class ReceiptCapabilityPolicy {
    public enum Capability { READ, EXPORT, DELETE, ARCHIVE }

    public static EnumSet<Capability> denied(EnumSet<Capability> allowed) {
        Objects.requireNonNull(allowed);
        return EnumSet.complementOf(allowed);
    }
}

Performance and ownership cost

Complement construction visits the enum universe and copies a compact bit representation, taking O(E) work in the number of enum constants under a portable cost model and O(E) result bits. The policy computation is small but should not replace explicit authorization checks at the action boundary.

Common Mistakes

  • Do not use a complement as granted permissions without reviewing new enum constants.
  • Do not assume the returned set is a live view of allowed.
  • Do not treat enum membership alone as proof that a caller is authorized.

Connected lessons

java
compact sets and views
enumset-complement-deny-policy
Storage details