diff options
Diffstat (limited to 'microservices/03-resource-server/src/main/java/com/example/resourceserver/config')
| -rw-r--r-- | microservices/03-resource-server/src/main/java/com/example/resourceserver/config/SecurityConfig.java | 32 |
1 files changed, 32 insertions, 0 deletions
diff --git a/microservices/03-resource-server/src/main/java/com/example/resourceserver/config/SecurityConfig.java b/microservices/03-resource-server/src/main/java/com/example/resourceserver/config/SecurityConfig.java new file mode 100644 index 0000000..7102e69 --- /dev/null +++ b/microservices/03-resource-server/src/main/java/com/example/resourceserver/config/SecurityConfig.java @@ -0,0 +1,32 @@ +package com.example.resourceserver.config; + +import org.springframework.context.annotation.Bean; +import org.springframework.context.annotation.Configuration; +import org.springframework.security.config.Customizer; +import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity; +import org.springframework.security.config.annotation.web.builders.HttpSecurity; +import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; +import org.springframework.security.web.SecurityFilterChain; + +@Configuration +@EnableWebSecurity +@EnableMethodSecurity +public class SecurityConfig { + + @Bean + public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { + http + .authorizeHttpRequests(authorize -> authorize + // 1. Specify the URL to allow without restrictions + .requestMatchers("/api/security/users/*/roles", "/public/**").permitAll() + // 2. Require authentication for all other requests + .anyRequest().authenticated() + ) + // 3. Configure the app as an OAuth2 Resource Server + .oauth2ResourceServer(oauth2 -> oauth2 + .jwt(Customizer.withDefaults()) + ); + + return http.build(); + } +} |
