405不允许POST的方法

Ara*_*ash 4 spring spring-security spring-boot

我有一个非常简单的spring启动应用程序,它由以下代码保护:

http.authorizeRequests()
        .antMatchers("/admin/**").access("hasRole('ROLE_ADMIN')")
        .and()
          .formLogin().loginPage("/login").failureUrl("/login?error")
          .usernameParameter("username").passwordParameter("password")
        .and()
          .logout().logoutSuccessUrl("/login?logout")
        .and()
          .exceptionHandling().accessDeniedPage("/403");
Run Code Online (Sandbox Code Playgroud)

我的想法是保护"管理员"部分.它公开了一个REST API.问题是所有的POSTS返回

405方法不允许

如果我从应用程序中删除安全启动器,它可以工作.这让我相信安全配置是个问题.但我无法弄清楚如何.

Ash*_*Rao 11

这应该很容易.

如果启用了CSRF,则不允许POST和PUT请求,并且弹出启动默认启用这些请求.

只需将其添加到配置代码中:

.csrf().disable()
Run Code Online (Sandbox Code Playgroud)

那是 :

http.
.csrf().disable().
authorizeRequests()
        .antMatchers("/admin/**").access("hasRole('ROLE_ADMIN')")
        .and()
          .formLogin().loginPage("/login").failureUrl("/login?error")
          .usernameParameter("username").passwordParameter("password")
        .and()
          .logout().logoutSuccessUrl("/login?logout")
        .and()
          .exceptionHandling().accessDeniedPage("/403");
Run Code Online (Sandbox Code Playgroud)

如果您需要启用CSRF,请参阅文档:

http://docs.spring.io/spring-security/site/docs/4.0.x/reference/htmlsingle/#csrf-configure