Kir*_*rov 1 spring-security spring-boot
我有配置
http.csrf().disable();
http.authorizeRequests()
.antMatchers("/**").authenticated()
.antMatchers("/shutdown").permitAll()
.and().formLogin().passwordParameter("password").usernameParameter("username")
.and().formLogin().loginPage("/authentication.html").permitAll()
.and().formLogin().loginProcessingUrl("/login")
.and().formLogin().failureUrl("/authentication.html")
.and().formLogin().defaultSuccessUrl("/",false);
Run Code Online (Sandbox Code Playgroud)
身份验证工作完美,但我无法在没有身份验证的情况下访问 /shutdown。这可能是什么原因?
/shutdown - 弹簧启动的关闭钩子。
如前所述,“/**”表示任何请求,并且只会使用匹配的第一个模式。需要注意的一件事是,您可以大量清理配置。请参阅下面的清洁版本:
http
.csrf().disable()
.authorizeRequests()
.antMatchers("/shutdown").permitAll()
.anyRequest().authenticated()
.and()
.formLogin()
.loginPage("/authentication.html")
.loginProcessingUrl("/login")
.failureUrl("/authentication.html")
.permitAll();
Run Code Online (Sandbox Code Playgroud)
变化亮点:
| 归档时间: |
|
| 查看次数: |
1315 次 |
| 最近记录: |