Ara*_*ash 4 spring spring-security spring-boot
我有一个非常简单的spring启动应用程序,它由以下代码保护:
http.authorizeRequests()
.antMatchers("/admin/**").access("hasRole('ROLE_ADMIN')")
.and()
.formLogin().loginPage("/login").failureUrl("/login?error")
.usernameParameter("username").passwordParameter("password")
.and()
.logout().logoutSuccessUrl("/login?logout")
.and()
.exceptionHandling().accessDeniedPage("/403");
Run Code Online (Sandbox Code Playgroud)
我的想法是保护"管理员"部分.它公开了一个REST API.问题是所有的POSTS返回
405方法不允许
如果我从应用程序中删除安全启动器,它可以工作.这让我相信安全配置是个问题.但我无法弄清楚如何.
Ash*_*Rao 11
这应该很容易.
如果启用了CSRF,则不允许POST和PUT请求,并且弹出启动默认启用这些请求.
只需将其添加到配置代码中:
.csrf().disable()
Run Code Online (Sandbox Code Playgroud)
那是 :
http.
.csrf().disable().
authorizeRequests()
.antMatchers("/admin/**").access("hasRole('ROLE_ADMIN')")
.and()
.formLogin().loginPage("/login").failureUrl("/login?error")
.usernameParameter("username").passwordParameter("password")
.and()
.logout().logoutSuccessUrl("/login?logout")
.and()
.exceptionHandling().accessDeniedPage("/403");
Run Code Online (Sandbox Code Playgroud)
如果您需要启用CSRF,请参阅文档:
http://docs.spring.io/spring-security/site/docs/4.0.x/reference/htmlsingle/#csrf-configure
| 归档时间: |
|
| 查看次数: |
6655 次 |
| 最近记录: |