【问题标题】:Adding spring security to Zuul service in spring boot micro service在spring boot微服务中为Zuul服务添加spring security
【发布时间】:2018-08-21 20:37:55
【问题描述】:
我是微服务架构的新手。
我们很少有zuul服务(api网关)、安全服务(连接db检查访问)和xyz服务。
我想知道,我们如何在 zuul 服务中定义的路由中添加 spring 安全性。 ?
在zuul服务上定义如下授权请求时,它应该在内部调用安全服务并对请求进行身份验证。
例子:
.authorizeRequests()
.antMatchers("/user/count").permitAll()
.antMatchers("/user/**").authenticated()
注意:/user 端点是在安全服务中定义的。
请帮帮我。
【问题讨论】:
标签:
spring
spring-boot
spring-security
netflix-zuul
【解决方案1】:
我们的 Zuul 代理支持 OAuth2 安全性。安全配置的示例如下:
@Configuration
@EnableResourceServer
public class JwtSecurityConfig extends ResourceServerConfigurerAdapter {
@Override
public void configure(HttpSecurity http) throws Exception {
http.authorizeRequests()
.antMatchers("/oauth/**").permitAll()
.antMatchers("/**").hasAuthority("ROLE_API_ACCESS")
.and()
.csrf().disable();
}
}
我假设如果您正在执行基本身份验证,您可以使用适当的类执行类似的操作。也许是这样的。
@Configuration
@Order(SecurityProperties.ACCESS_OVERRIDE_ORDER)
public class SecurityConfig extends WebSecurityConfigurerAdapter {
@Override
protected void configure(HttpSecurity http) throws Exception {
BasicAuthenticationEntryPoint authenticationEntryPoint = new BasicAuthenticationEntryPoint();
authenticationEntryPoint
.setRealmName("EnterpriseDeviceAuthentication");
http
.authorizeRequests()
.antMatchers("/health").permitAll() // allow access to health page
.antMatchers("/somepath").permitAll()
.antMatchers("/somepath2").permitAll()
.antMatchers("/bootstrap.min.css").permitAll()
.anyRequest().hasAnyAuthority(SecurityRoles.ALL_SECURITY_ROLES)
.and().httpBasic()
.authenticationEntryPoint(authenticationEntryPoint)
.and()
.csrf().disable();
}
}