【发布时间】:2021-06-06 11:34:10
【问题描述】:
我正在尝试使用多个入口点来保护我的 Spring Boot 应用程序,具体取决于用户。
我有 3 种身份验证:
- 系统用户的基本 http 用户名和密码
- 普通用户的 OAuth
- 用户注册/登录后的Jwt
这个想法是让 /register、/login 和 /token 端点在 OAuth 身份验证后可访问。 对于系统用户,/register、/login 和 /token 端点只能通过用户名和密码访问。 所有其他端点只能通过从 /login 或 /token 端点获得的 JWT 令牌访问。
为此我设置了 3 个 WebSecurityConfigurer:
@Configuration
@Order(1)
public class BasicWebSecurityConfigurationAdapter extends WebSecurityConfigurerAdapter {
@Autowired
private UserDetailsService userDetailsService;
@Override
protected void configure(HttpSecurity http) throws Exception {
http.csrf().disable()
.antMatcher("/api/v1/system/**")
.authorizeRequests()
.anyRequest()
.authenticated()
.and()
.httpBasic();
}
@Override
public void configure(AuthenticationManagerBuilder auth)
throws Exception {
auth
.userDetailsService(userDetailsService)
.passwordEncoder(new BCryptPasswordEncoder());
}
@Bean
@Override
public AuthenticationManager authenticationManagerBean() throws Exception {
return super.authenticationManagerBean();
}
}
@Configuration
@Order(2)
public class OAuthWebSecurityConfigurerAdapter extends WebSecurityConfigurerAdapter {
@Override
protected void configure(HttpSecurity http) throws Exception {
http.csrf().disable()
.antMatcher("/api/v1/access/**")
.authorizeRequests()
.anyRequest()
.authenticated()
.and()
.oauth2Login();
}
}
@Configuration
@Order(3)
public class JwtWebSecurityConfigurerAdapter extends WebSecurityConfigurerAdapter {
@Override
protected void configure(HttpSecurity http) throws Exception {
http.csrf().disable()
.antMatcher("/api/v1/**")
.authorizeRequests()
.anyRequest()
.authenticated();
http
.addFilterBefore(new JwtAuthenticationFilter(), UsernamePasswordAuthenticationFilter.class);
http
.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS);
}
}
我遇到的问题是 OAuth 配置。找不到以下网址
http://localhost:8080/oauth2/authorization/google
我想 antMatcher 隐藏了其他端点?
有人可以帮忙吗?
谢谢
【问题讨论】:
标签: spring-security