【问题标题】:Nginx reverse proxy allow only authenticated users to spring boot apiNginx 反向代理只允许经过身份验证的用户使用 Spring Boot api
【发布时间】:2020-11-13 07:50:28
【问题描述】:

我的任务是用 Nginx 替换 Zuul 反向代理。 Zuul 代理中的安全性通过implementation 'org.springframework.boot:spring-boot-starter-security' 实现

@EnableWebSecurity
class ZuulSecurity(...) : WebSecurityConfigurerAdapter() {

    override fun configure(http: HttpSecurity) {
        http.csrf().disable().httpBasic().disable()
                .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.NEVER)
                .sessionFixation().changeSessionId()
                .and().authorizeRequests()
                .antMatchers(*dennyPatterns).denyAll()
                .antMatchers(*loginPatterns).permitAll()
                .anyRequest().authenticated()
                .and().formLogin().loginPage(loginUrl)
    }
}

Spring boot api 服务的保护方式与@EnableWebSecurity类似

我将 Zuul 反向代理替换为 Nginx 作为反向代理。

我如何在 Nginx 上强制执行安全性,以便没有未经身份验证的请求被proxy_pass'ed 到后端 api 服务? - 换句话说,如果请求是由经过身份验证的用户发出的,我想在 Nginx 上进行验证(loginPatterns url 有一些例外)。我应该学习nginx/admin-guide/security-controls中的哪一个?

【问题讨论】:

    标签: java spring spring-boot nginx spring-security


    【解决方案1】:

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 2015-05-16
      • 2020-01-01
      • 2017-04-23
      • 2017-07-08
      • 2017-04-17
      • 2015-05-01
      • 2012-03-09
      相关资源
      最近更新 更多