替换spring boot中的websecurityconfigureradapter for ResourceserverConfigurerAdapter
由于Spring Boot 2.7.x版本WebsEcurityConfigurerAdapter
class class class necrecectect and a 指南来自Spring.io如何替换这些类并使用基于组件的安全配置。
我的问题是如何处理以下用例:
@Configuration
@EnableResourceServer
public class BearerAuthWebSecurityConfiguration extends ResourceServerConfigurerAdapter {
@Override
public void configure(HttpSecurity http) throws Exception {
http
.antMatcher("/api/**")
.sessionManagement()
.sessionCreationPolicy(SessionCreationPolicy.STATELESS)
.and()
.authorizeRequests()
.anyRequest()
.authenticated();
}
@Override
public void configure(ResourceServerSecurityConfigurer resources) {
resources.resourceId(null);
resources.authenticationManager(new OAuth2AuthenticationManager());
}
}
我找不到有关如何处理@enableReSourceserver
和ResourceerverConfigurerAdapter
使用新的基于组件的安全配置的指南。在引擎盖下,这些类还使用websecurityConfigurerAdapter
,应移至基于组件的安全配置。
Since Spring Boot 2.7.x version WebSecurityConfigurerAdapter
class is deprecated and there is a guide from spring.io on how to replace those classes and use component-based security configuration.
My question is how to handle the following use-case:
@Configuration
@EnableResourceServer
public class BearerAuthWebSecurityConfiguration extends ResourceServerConfigurerAdapter {
@Override
public void configure(HttpSecurity http) throws Exception {
http
.antMatcher("/api/**")
.sessionManagement()
.sessionCreationPolicy(SessionCreationPolicy.STATELESS)
.and()
.authorizeRequests()
.anyRequest()
.authenticated();
}
@Override
public void configure(ResourceServerSecurityConfigurer resources) {
resources.resourceId(null);
resources.authenticationManager(new OAuth2AuthenticationManager());
}
}
I did not find any guide on how to handle @EnableResourceServer
and ResourceServerConfigurerAdapter
using the new component-based security configuration. And under the hood these classes also use WebSecurityConfigurerAdapter
and should be moved to the component-based security configuration.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
The
ResourceServerSecurityConfigurer
is from theThe
ResourceServerSecurityConfigurer
is from the EOL'dspring-security-oauth
project, therefore there is no support for new features/deprecations. I recommend you to use Spring Security's support for OAuth 2.0.