zoukankan      html  css  js  c++  java
  • SpringSecurity常见用法备忘

    package com.botao.securitydemo1.config;
    
    import com.botao.securitydemo1.Service.UserService;
    import org.springframework.context.annotation.Bean;
    import org.springframework.context.annotation.Configuration;
    import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
    import org.springframework.security.config.annotation.web.builders.HttpSecurity;
    import org.springframework.security.config.annotation.web.builders.WebSecurity;
    import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
    import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
    import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
    import org.springframework.security.crypto.password.PasswordEncoder;
    
    import java.util.ArrayList;
    import java.util.Collection;
    
    @EnableWebSecurity
    public class SecurityConfig extends WebSecurityConfigurerAdapter {
    
        @Bean
        public BCryptPasswordEncoder bCryptPasswordEncoder(){
            return new BCryptPasswordEncoder();
        }
    
        @Override
        protected void configure(HttpSecurity http) throws Exception {
            /**
             * 请求授权的规则
             */
            http.authorizeRequests()
                    .antMatchers("/").permitAll()
                    .antMatchers("/a/**").hasRole("vip1")
                    .antMatchers("/b/**").hasRole("vip2")
                    .antMatchers("/c/**").hasRole("vip3").anyRequest().authenticated();
            http.formLogin();
    
            //登录
            //http.formLogin().loginPage("/login").loginProcessingUrl("/check").usernameParameter("username").passwordParameter("psw");
            //退出
            //http.logout().logoutUrl("/logout").logoutSuccessUrl("/").permitAll();
            //记住我
            //http.rememberMe().rememberMeParameter("remember");
            //关闭csrf
            http.csrf().disable();
    
            //没有权限就进xxx.html(403)
            //http.exceptionHandling().accessDeniedPage("/xxx.html");
        }
    
    
        //认证
        @Override
        protected void configure(AuthenticationManagerBuilder auth) throws Exception {
    
            auth.inMemoryAuthentication().passwordEncoder(new BCryptPasswordEncoder())
                    .withUser("a").password(new BCryptPasswordEncoder().encode("123456")).roles("vip1")
                    .and()
                    .withUser("b").password(new BCryptPasswordEncoder().encode("123456")).roles("vip2")
                    .and()
                    .withUser("c").password(new BCryptPasswordEncoder().encode("123456")).roles("ivp3")
                    .and()
                    .withUser("admin").password(new BCryptPasswordEncoder().encode("123456")).roles("vip1", "vip2", "vip3");
    
        }
    }
  • 相关阅读:
    C++函数参数传参的本质解析
    C#值类型和引用类型详解
    C#学习笔记(转换)
    C#学习笔记(泛型)
    # Java反射2——获取实体所有属性和方法,并对属性赋值
    Java反射1——扫描某个包下的所有类
    JSR教程2——Spring MVC数据校验与国际化
    JSR教程1——JSR 303
    Github如何撤销提交并清除痕迹
    论文第5章:Android绘图平台的实现
  • 原文地址:https://www.cnblogs.com/botaoJava/p/13866954.html
Copyright © 2011-2022 走看看