diff options
| author | Kamal Wickramanayake <kamal@inbox.lk> | 2026-07-03 19:02:36 +0530 |
|---|---|---|
| committer | Kamal Wickramanayake <kamal@inbox.lk> | 2026-07-03 19:02:36 +0530 |
| commit | aa122113ade36f02dc8fdbebdf1232b5c4b8742c (patch) | |
| tree | c345b83db6c769bf5e72a09e3f19d43431961695 /microservices/03-resource-server/src/main/java/com/example/resourceserver/config/SecurityConfig.java | |
| parent | b221a83ecef1dd7f9583d5107017d24e668205a6 (diff) | |
Microservice sample projects
Diffstat (limited to 'microservices/03-resource-server/src/main/java/com/example/resourceserver/config/SecurityConfig.java')
| -rw-r--r-- | microservices/03-resource-server/src/main/java/com/example/resourceserver/config/SecurityConfig.java | 32 |
1 files changed, 32 insertions, 0 deletions
diff --git a/microservices/03-resource-server/src/main/java/com/example/resourceserver/config/SecurityConfig.java b/microservices/03-resource-server/src/main/java/com/example/resourceserver/config/SecurityConfig.java new file mode 100644 index 0000000..7102e69 --- /dev/null +++ b/microservices/03-resource-server/src/main/java/com/example/resourceserver/config/SecurityConfig.java @@ -0,0 +1,32 @@ +package com.example.resourceserver.config; + +import org.springframework.context.annotation.Bean; +import org.springframework.context.annotation.Configuration; +import org.springframework.security.config.Customizer; +import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity; +import org.springframework.security.config.annotation.web.builders.HttpSecurity; +import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; +import org.springframework.security.web.SecurityFilterChain; + +@Configuration +@EnableWebSecurity +@EnableMethodSecurity +public class SecurityConfig { + + @Bean + public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { + http + .authorizeHttpRequests(authorize -> authorize + // 1. Specify the URL to allow without restrictions + .requestMatchers("/api/security/users/*/roles", "/public/**").permitAll() + // 2. Require authentication for all other requests + .anyRequest().authenticated() + ) + // 3. Configure the app as an OAuth2 Resource Server + .oauth2ResourceServer(oauth2 -> oauth2 + .jwt(Customizer.withDefaults()) + ); + + return http.build(); + } +} |
