summaryrefslogtreecommitdiff
path: root/spring-boot/10-role-based-security/README
diff options
context:
space:
mode:
Diffstat (limited to 'spring-boot/10-role-based-security/README')
-rw-r--r--spring-boot/10-role-based-security/README20
1 files changed, 20 insertions, 0 deletions
diff --git a/spring-boot/10-role-based-security/README b/spring-boot/10-role-based-security/README
new file mode 100644
index 0000000..9a79809
--- /dev/null
+++ b/spring-boot/10-role-based-security/README
@@ -0,0 +1,20 @@
+This sample project shows how to use role base security in a Spring Boot application.
+
+To run with support for hot swap during development, use the dev profile as follows:
+
+ mvn spring-boot:run -Dspring-boot.run.profiles=dev
+
+User/Pasword (as defined in resources/data.sql)
+
+ admin: abc123
+ user1: abc123
+
+How is role based security enabled?
+
+1. entity/User.java has been updated to return a list of SimpleGrantAuthority objects in the getAuthorities() method.
+
+2. config/SecurityConfig.java has been updated to enable web security and method security.
+
+3. Controllers and services can be annotated with @PreAuthorize(). Example: ContractController.java
+
+4. In Thymeleaf templates, sec:authorize() works with role names. Example: layout/main.html \ No newline at end of file