summaryrefslogtreecommitdiff
path: root/spring-boot/10-role-based-security/README
blob: 9a7980981241145a5eab736e1a087f8d0b97ca0c (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
This sample project shows how to use role base security in a Spring Boot application.

To run with support for hot swap during development, use the dev profile as follows:

  mvn spring-boot:run -Dspring-boot.run.profiles=dev

User/Pasword (as defined in resources/data.sql)

  admin: abc123
  user1: abc123

How is role based security enabled?

1. entity/User.java has been updated to return a list of SimpleGrantAuthority objects in the getAuthorities() method.

2. config/SecurityConfig.java has been updated to enable web security and method security.

3. Controllers and services can be annotated with @PreAuthorize(). Example: ContractController.java

4. In Thymeleaf templates, sec:authorize() works with role names. Example: layout/main.html