You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
102 lines
3.8 KiB
102 lines
3.8 KiB
/* |
|
* Copyright 2012-2016 the original author or authors. |
|
* |
|
* Licensed under the Apache License, Version 2.0 (the "License"); |
|
* you may not use this file except in compliance with the License. |
|
* You may obtain a copy of the License at |
|
* |
|
* http://www.apache.org/licenses/LICENSE-2.0 |
|
* |
|
* Unless required by applicable law or agreed to in writing, software |
|
* distributed under the License is distributed on an "AS IS" BASIS, |
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|
* See the License for the specific language governing permissions and |
|
* limitations under the License. |
|
*/ |
|
|
|
package sample.security.method; |
|
|
|
import java.util.Date; |
|
import java.util.Map; |
|
|
|
import org.springframework.boot.autoconfigure.SpringBootApplication; |
|
import org.springframework.boot.autoconfigure.security.SecurityProperties; |
|
import org.springframework.boot.builder.SpringApplicationBuilder; |
|
import org.springframework.context.annotation.Bean; |
|
import org.springframework.context.annotation.Configuration; |
|
import org.springframework.core.Ordered; |
|
import org.springframework.core.annotation.Order; |
|
import org.springframework.security.access.annotation.Secured; |
|
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; |
|
import org.springframework.security.config.annotation.authentication.configurers.GlobalAuthenticationConfigurerAdapter; |
|
import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity; |
|
import org.springframework.security.config.annotation.web.builders.HttpSecurity; |
|
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; |
|
import org.springframework.security.web.util.matcher.AntPathRequestMatcher; |
|
import org.springframework.stereotype.Controller; |
|
import org.springframework.web.bind.annotation.RequestMapping; |
|
import org.springframework.web.servlet.config.annotation.ViewControllerRegistry; |
|
import org.springframework.web.servlet.config.annotation.WebMvcConfigurerAdapter; |
|
|
|
@SpringBootApplication |
|
@EnableGlobalMethodSecurity(securedEnabled = true) |
|
public class SampleMethodSecurityApplication extends WebMvcConfigurerAdapter { |
|
|
|
@Controller |
|
protected static class HomeController { |
|
|
|
@RequestMapping("/") |
|
@Secured("ROLE_ADMIN") |
|
public String home(Map<String, Object> model) { |
|
model.put("message", "Hello World"); |
|
model.put("title", "Hello Home"); |
|
model.put("date", new Date()); |
|
return "home"; |
|
} |
|
|
|
} |
|
|
|
@Override |
|
public void addViewControllers(ViewControllerRegistry registry) { |
|
registry.addViewController("/login").setViewName("login"); |
|
registry.addViewController("/access").setViewName("access"); |
|
} |
|
|
|
@Bean |
|
public ApplicationSecurity applicationSecurity() { |
|
return new ApplicationSecurity(); |
|
} |
|
|
|
public static void main(String[] args) throws Exception { |
|
new SpringApplicationBuilder(SampleMethodSecurityApplication.class).run(args); |
|
} |
|
|
|
@Order(Ordered.HIGHEST_PRECEDENCE) |
|
@Configuration |
|
protected static class AuthenticationSecurity |
|
extends GlobalAuthenticationConfigurerAdapter { |
|
|
|
@Override |
|
public void init(AuthenticationManagerBuilder auth) throws Exception { |
|
auth.inMemoryAuthentication().withUser("admin").password("admin") |
|
.roles("ADMIN", "USER").and().withUser("user").password("user") |
|
.roles("USER"); |
|
} |
|
|
|
} |
|
|
|
@Order(SecurityProperties.ACCESS_OVERRIDE_ORDER) |
|
protected static class ApplicationSecurity extends WebSecurityConfigurerAdapter { |
|
|
|
@Override |
|
protected void configure(HttpSecurity http) throws Exception { |
|
http.authorizeRequests().antMatchers("/login").permitAll().anyRequest() |
|
.fullyAuthenticated().and().formLogin().loginPage("/login") |
|
.failureUrl("/login?error").and().logout() |
|
.logoutRequestMatcher(new AntPathRequestMatcher("/logout")).and() |
|
.exceptionHandling().accessDeniedPage("/access?error"); |
|
} |
|
|
|
} |
|
|
|
}
|
|
|