【发布时间】:2019-12-12 06:19:43
【问题描述】:
我想在启用 Spring Security 的 Spring Boot 项目中使用 h2-console。我的配置如下所示,但我无法访问任何未经身份验证的路径。如果我打开控制台路径,则会出现 Loginprompt。
是不是顺序不对?
我已经用 WebSecurityConfigurerAdapter 尝试了旧方法并且它有效,但我想使用新的东西。
@EnableWebFluxSecurity
public class SecurityConfiguration {
@Bean
public SecurityWebFilterChain springSecurityFilterChain(ServerHttpSecurity http) {
return http
.csrf().disable()
.headers().frameOptions().disable().and()
.authorizeExchange()
.anyExchange().permitAll()
.and()
.httpBasic().and()
.build();
}
}
我将配置更改为以下内容,并且验证排除了我预期的 h2 控制台:
@Configuration
public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
@Override
protected void configure(HttpSecurity http) throws Exception {
http.headers().frameOptions().disable().and()
.csrf().disable();
http
.authorizeRequests()
.antMatchers("/", "/h2-console/**").permitAll()
.anyRequest().authenticated()
.and()
.formLogin()
.permitAll()
.and()
.logout()
.permitAll();
}
}
【问题讨论】:
-
如果您将以下内容添加到您的安全类中会发生什么:.antMatchers("/h2-console/**") 或阅读此内容:appsdeveloperblog.com/…
-
Antmatchers 仅存在于 WebSecurityConfigurerAdapter (HttpSecurity) 中,而不存在于 WebFlux (ServerHttpSecurity) 中,还是我遗漏了什么?
-
我尝试了 pathMatcher("/h2-console/**").permitAll(),但没有帮助。
标签: java spring-boot spring-security h2 spring-webflux