From 41b068b6d48f9d82babd1cfce3520ad0b28be861 Mon Sep 17 00:00:00 2001 From: Kamal Wickramanayake Date: Sat, 20 Jun 2026 18:25:56 +0530 Subject: Added Spring Boot role based security sample application --- spring-boot/10-role-based-security/README | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 spring-boot/10-role-based-security/README (limited to 'spring-boot/10-role-based-security/README') diff --git a/spring-boot/10-role-based-security/README b/spring-boot/10-role-based-security/README new file mode 100644 index 0000000..9a79809 --- /dev/null +++ b/spring-boot/10-role-based-security/README @@ -0,0 +1,20 @@ +This sample project shows how to use role base security in a Spring Boot application. + +To run with support for hot swap during development, use the dev profile as follows: + + mvn spring-boot:run -Dspring-boot.run.profiles=dev + +User/Pasword (as defined in resources/data.sql) + + admin: abc123 + user1: abc123 + +How is role based security enabled? + +1. entity/User.java has been updated to return a list of SimpleGrantAuthority objects in the getAuthorities() method. + +2. config/SecurityConfig.java has been updated to enable web security and method security. + +3. Controllers and services can be annotated with @PreAuthorize(). Example: ContractController.java + +4. In Thymeleaf templates, sec:authorize() works with role names. Example: layout/main.html \ No newline at end of file -- cgit v1.2.3