【发布时间】:2018-11-08 18:25:55
【问题描述】:
我有以下代码...
private static Collection<? extends GrantedAuthority>
readAuthorities(DecodedJWT jwt) {
...
return authorities;
}
它显示了一个Admin 角色。但是,当我尝试通过...访问网站时...
protected void configure(HttpSecurity http) throws Exception {
http.csrf().disable();
http.antMatchers(ADMIN).hasRole(Role.ADMIN.getRoleName())
....
}
// Role.ADMIN.getRoleName() == "Admin"
但是当我访问需要管理员权限的站点时,我得到了 403。
我错过了什么?
【问题讨论】:
-
您的安全类需要扩展“WebSecurityConfigurerAdapter”,还需要使用“@Configuration”和“@EnableWebSecurity”对其进行注释。它可能正在这样做,但我无法用你的样本来判断。当您删除 antMatchers 角色时,它会起作用吗?
-
已经有注释了
-
是的,如果我删除该行并仅依赖身份验证,它确实有效
标签: spring-security