【问题标题】:Disabling authentication in “OAUTH2” enabled boot application在启用“OAUTH2”的启动应用程序中禁用身份验证
【发布时间】:2018-06-13 21:43:58
【问题描述】:

如何在启用“OAUTH2”的 spring-boot 应用程序中禁用身份验证? 这通常是测试或构建阶段所必需的。

【问题讨论】:

    标签: spring spring-boot spring-security oauth-2.0


    【解决方案1】:

    当我们想要进行测试/构建并且我们没有即时可用的 OAuth2 令牌时,这是一个有效的场景。 以下是要遵循的步骤:

    1. 创建一个没有 OAuth2 配置的 YAML 文件(即application-{profile_name}.yml)并在其中添加以下属性:

      Security.ignored = /** 
      security.basic.enable=false
      
    2. 添加一个绕过 HTTP/S 请求授权的类。注意:此类应具有相同的配置文件名称(即{profile_name})。

      @Profile({"profile_name"})
      public class DisableOAuth2Config {
      
          @Bean
          public ResourceServerConfigurer resourceServerConfigurer() {
              return new ResourceServerConfigurerAdapter() {
                  @Override
                  public void configure(HttpSecurity http) throws Exception {
                      http
                          .authorizeRequests()
                              .antMatchers("/**").permitAll();
                  }
              };
          }
      }
      
    3. 在SecurityConfiguration 类中提供Profile,我们仍然希望有安全性。 @Profile({"local","dev","aws"}),这将区分启用/禁用安全性的配置文件。

    4. 注意:请检查注释@EnableResourceServe、@EnableWebSecurity 和@EnableGlobalMethodSecurity(prePostEnabled = true)。它们应该仅在 SecurityConfiguration 类中可用。不是多个地方,也不是SpringBoot 类。

    【讨论】:

      猜你喜欢
      • 2013-12-23
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2017-10-25
      • 2022-10-23
      • 2012-06-04
      • 1970-01-01
      相关资源
      最近更新 更多