【发布时间】:2017-08-22 19:37:13
【问题描述】:
在 Spring Security 中:
<sec:http pattern="/api/**" create-session="never"
entry-point-ref="oauthAuthenticationEntryPoint"
access-decision-manager-ref="accessDecisionManager"
xmlns="http://www.springframework.org/schema/security">
<anonymous enabled="false" />
<intercept-url pattern="/api/**" access="ROLE_ADMIN" />
<custom-filter ref="resourceServerFilter" before="PRE_AUTH_FILTER" />
<access-denied-handler ref="oauthAccessDeniedHandler" />
</sec:http>
在这一行<intercept-url pattern="/api/**" access="ROLE_ADMIN" />
如果我写有什么区别:
<intercept-url pattern="/api/**" access="hasRole('ROLE_ADMIN')" />
或:
<intercept-url pattern="/api/**" access="hasAnyRole('ROLE_ADMIN')" />
【问题讨论】:
标签: java spring spring-security