You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
56 lines
1.9 KiB
56 lines
1.9 KiB
/* |
|
* Copyright 2020-2023 the original author or authors. |
|
* |
|
* Licensed under the Apache License, Version 2.0 (the "License"); |
|
* you may not use this file except in compliance with the License. |
|
* You may obtain a copy of the License at |
|
* |
|
* https://www.apache.org/licenses/LICENSE-2.0 |
|
* |
|
* Unless required by applicable law or agreed to in writing, software |
|
* distributed under the License is distributed on an "AS IS" BASIS, |
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|
* See the License for the specific language governing permissions and |
|
* limitations under the License. |
|
*/ |
|
package sample.config; |
|
|
|
import org.springframework.context.annotation.Bean; |
|
import org.springframework.context.annotation.Configuration; |
|
import org.springframework.security.config.Customizer; |
|
import org.springframework.security.config.annotation.web.builders.HttpSecurity; |
|
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; |
|
import org.springframework.security.config.annotation.web.configuration.WebSecurityCustomizer; |
|
import org.springframework.security.web.SecurityFilterChain; |
|
import org.springframework.security.web.authentication.LoginUrlAuthenticationEntryPoint; |
|
|
|
/** |
|
* @author Steve Riesenberg |
|
* @since 1.1 |
|
*/ |
|
@Configuration |
|
@EnableWebSecurity |
|
public class SecurityConfig { |
|
|
|
@Bean |
|
public WebSecurityCustomizer webSecurityCustomizer() { |
|
return (web) -> web.ignoring().requestMatchers("/webjars/**", "/assets/**"); |
|
} |
|
|
|
@Bean |
|
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { |
|
// @formatter:off |
|
http |
|
.authorizeHttpRequests((authorize) -> authorize |
|
.requestMatchers("/", "/authorize").permitAll() |
|
.anyRequest().authenticated() |
|
) |
|
.exceptionHandling((exceptions) -> exceptions |
|
.authenticationEntryPoint(new LoginUrlAuthenticationEntryPoint("/")) |
|
) |
|
.oauth2Client(Customizer.withDefaults()); |
|
// @formatter:on |
|
return http.build(); |
|
} |
|
|
|
}
|
|
|