【问题标题】:Get request is not authorized when CSRF is disabled in Spring Security在 Spring Security 中禁用 CSRF 时获取请求未授权
【发布时间】:2018-10-08 14:41:00
【问题描述】:

如果我不添加以下内容,Spring Security 基本身份验证将起作用

@Configuration
@EnableWebSecurity
public class WebSecurityConfiguration extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.csrf().disable();
    }
}

在我添加此代码后,一个没有授权标头的 GET 请求会获得响应,而我希望得到一个未授权的响应。在添加此配置之前,GET 响应会得到401。

唯一的变化是上面的类;没有其他任何改变。

【问题讨论】:

  • 检查 http .authorizeRequests() .antMatchers(HttpMethod.GET, "/request-url").permitAll()

标签: spring spring-security


【解决方案1】:

尝试添加.anyRequest().authenticated(),表示所有请求都必须经过身份验证。如果您想添加豁免,请添加 .antMatchers(HttpMethod.GET, "/", "/js/**", "/css/*", "/images/**").permitAll() 之类的内容,这将不会通过身份验证。

示例代码:

@Configuration
@EnableWebSecurity
public class WebSecurityConfiguration extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.csrf().disable().authorizeRequests()
            .antMatchers(HttpMethod.GET, "/", "/js/**", "/css/*", "/images/**").permitAll()
            .anyRequest().authenticated();
    }
}

【讨论】:

    猜你喜欢
    • 2020-05-11
    • 2023-01-11
    • 2015-10-21
    • 1970-01-01
    • 1970-01-01
    • 2020-07-28
    • 2018-12-04
    • 2015-10-04
    • 2020-04-20
    相关资源
    最近更新 更多