【发布时间】:2020-04-18 05:31:34
【问题描述】:
我正在使用 Spring boot(和 Spring Security)和 Angular 开发我的 API。
你的 TypeScript 代码:
return this.http.post<any>('http://localhost:8080/users',
{
firstName: 'Clemi',
lastName: 'Le boss',
mail: 'clemclem'
});
我的控制器:
@RestController
@RequestMapping(path = "/users")
public class UserController
{
@Autowired
private UserService userService;
...
@PostMapping()
public ResponseEntity<Object> addUser(Principal principal, @RequestBody User user) {
User savedUser = userService.save(user);
return new ResponseEntity<Object>(HttpStatus.OK);
}
}
以及安全配置:
@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {
@Autowired
UserService userDetailsService;
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
auth.userDetailsService(userDetailsService).passwordEncoder(bCryptPasswordEncoder());
}
@Override
protected void configure(HttpSecurity http) throws Exception {
http.csrf()
.disable()
.exceptionHandling()
.authenticationEntryPoint(new Http403ForbiddenEntryPoint() {
})
.and()
.authenticationProvider(getProvider())
.formLogin()
.loginProcessingUrl("/login")
.successHandler(new AuthentificationLoginSuccessHandler())
.failureHandler(new SimpleUrlAuthenticationFailureHandler())
.and()
.logout()
.logoutUrl("/logout")
.logoutSuccessHandler(new AuthentificationLogoutSuccessHandler())
.invalidateHttpSession(true)
.and()
.authorizeRequests()
.antMatchers("/login").permitAll()
.antMatchers("/logout").permitAll()
.antMatchers(HttpMethod.GET, "/users/**").authenticated()
.antMatchers(HttpMethod.DELETE, "/users/**").hasRole("ADMIN")
.antMatchers(HttpMethod.PUT).hasRole("USER")
.anyRequest().permitAll()
.and()
.httpBasic();
}
@Bean
public BCryptPasswordEncoder bCryptPasswordEncoder() {
return new BCryptPasswordEncoder();
}
private class AuthentificationLoginSuccessHandler extends SimpleUrlAuthenticationSuccessHandler {
@Override
public void onAuthenticationSuccess(HttpServletRequest request,
HttpServletResponse response, Authentication authentication)
throws IOException, ServletException {
response.setStatus(HttpServletResponse.SC_OK);
}
}
private class AuthentificationLogoutSuccessHandler extends SimpleUrlLogoutSuccessHandler {
@Override
public void onLogoutSuccess(HttpServletRequest request, HttpServletResponse response,
Authentication authentication) throws IOException, ServletException {
response.setStatus(HttpServletResponse.SC_OK);
}
}
@Bean
public AuthenticationProvider getProvider() {
AuthService provider = new AuthService();
provider.setUserDetailsService(userDetailsService);
provider.setPasswordEncoder(bCryptPasswordEncoder());
return provider;
}
}
当我使用邮递员时,我的请求工作正常。但是当我使用我的前端时,每个请求都变成了 OPTIONS 请求。我阅读了多篇文章,解释这是因为 Cross Origin Request 并且可能是“预检请求”,但我不知道如何解决它......
有什么想法吗?
【问题讨论】:
-
在生产中,您是否计划从同一个 URL 为 Angular 应用程序和 REST 服务提供服务?如果是这样,让 ng 充当 Spring 的反向代理:github.com/angular/angular-cli/blob/master/docs/documentation/…,并从您的 URL 中删除“localhost:8080”(这对您自己的开发机器没有任何意义)。
-
您需要将
HttpMethod.OPTIONS列入白名单
标签: java angular typescript spring-boot spring-security