代码之家  ›  专栏  ›  技术社区  ›  Christos Karapapas

使用Spring安全性限制对新引入角色的控制器类中某些方法的访问

  •  -1
  • Christos Karapapas  · 技术社区  · 7 年前

    控制器方法的默认行为是什么 @PreAuthorize("hasRole('ROLE_xxxx')") 或 @Secured("ROLE_xxxx") 注释。
    哪些角色可以使用这些方法?每个经过身份验证的用户都能调用这些方法吗?

    考虑到以下情况。
    @PreAuthorize 或 @Secured

    1 回复  |  直到 7 年前
        1
  •  1
  •   ninj    7 年前

    在到达控制器之前,可以尝试在http级别进行安全保护。

    protected void configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()                                                               
                .antMatchers("/resources/**", "/signup", "/about").permitAll()                  
                .antMatchers("/admin/**").hasRole("ADMIN")                                      
                .antMatchers("/db/**").access("hasRole('ADMIN') and hasRole('DBA')")            
                .anyRequest().authenticated()                                                   
            .and()
            // ...
            .formLogin();
    }
    

    请参见: https://docs.spring.io/spring-security/site/docs/current/reference/htmlsingle/#jc-httpsecurity

    推荐文章