blob: 95aaa8a5ef45201e75e765069d092573ee6a2782 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
|
This sample project shows how to use role base security in a Spring Boot application.
To run with support for hot swap during development, use the dev profile as follows:
mvn spring-boot:run -Dspring-boot.run.profiles=dev
User/Pasword (as defined in resources/data.sql)
admin: abc123
user1: abc123
How is role based security enabled?
1. entity/User.java has been updated to return a list of SimpleGrantAuthority objects in the getAuthorities() method.
2. config/SecurityConfig.java has been updated to enable web security and method security.
3. Controllers and services can be annotated with @PreAuthorize(). Example: ContractController.java
4. In Thymeleaf templates, sec:authorize() works with role names. Example: layout/main.html
What other modifications are found in this sample app?
1. List of users are shown in a table. UserRepository extends JPARepository class that supports paging and sorting.
2. The edit link for each user can be used to show the update form.
3. Error pages have been added. See templates/error.html and templates/error/403.html .
|