• SpringSecurity常见用法备忘


    package com.botao.securitydemo1.config;
    
    import com.botao.securitydemo1.Service.UserService;
    import org.springframework.context.annotation.Bean;
    import org.springframework.context.annotation.Configuration;
    import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
    import org.springframework.security.config.annotation.web.builders.HttpSecurity;
    import org.springframework.security.config.annotation.web.builders.WebSecurity;
    import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
    import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
    import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
    import org.springframework.security.crypto.password.PasswordEncoder;
    
    import java.util.ArrayList;
    import java.util.Collection;
    
    @EnableWebSecurity
    public class SecurityConfig extends WebSecurityConfigurerAdapter {
    
        @Bean
        public BCryptPasswordEncoder bCryptPasswordEncoder(){
            return new BCryptPasswordEncoder();
        }
    
        @Override
        protected void configure(HttpSecurity http) throws Exception {
            /**
             * 请求授权的规则
             */
            http.authorizeRequests()
                    .antMatchers("/").permitAll()
                    .antMatchers("/a/**").hasRole("vip1")
                    .antMatchers("/b/**").hasRole("vip2")
                    .antMatchers("/c/**").hasRole("vip3").anyRequest().authenticated();
            http.formLogin();
    
            //登录
            //http.formLogin().loginPage("/login").loginProcessingUrl("/check").usernameParameter("username").passwordParameter("psw");
            //退出
            //http.logout().logoutUrl("/logout").logoutSuccessUrl("/").permitAll();
            //记住我
            //http.rememberMe().rememberMeParameter("remember");
            //关闭csrf
            http.csrf().disable();
    
            //没有权限就进xxx.html(403)
            //http.exceptionHandling().accessDeniedPage("/xxx.html");
        }
    
    
        //认证
        @Override
        protected void configure(AuthenticationManagerBuilder auth) throws Exception {
    
            auth.inMemoryAuthentication().passwordEncoder(new BCryptPasswordEncoder())
                    .withUser("a").password(new BCryptPasswordEncoder().encode("123456")).roles("vip1")
                    .and()
                    .withUser("b").password(new BCryptPasswordEncoder().encode("123456")).roles("vip2")
                    .and()
                    .withUser("c").password(new BCryptPasswordEncoder().encode("123456")).roles("ivp3")
                    .and()
                    .withUser("admin").password(new BCryptPasswordEncoder().encode("123456")).roles("vip1", "vip2", "vip3");
    
        }
    }
  • 相关阅读:
    canvas beginPath()的初步理解
    高效取余运算(n-1)&hash原理探讨
    EntityUtils.toString(entity)处理字符集问题解决
    python计算不规则图形面积算法
    VMware与 Device/Credential Guard 不兼容,解决办法及心得
    Java爬取51job保存到MySQL并进行分析
    纯C语言实现循环双向链表创建,插入和删除
    纯C语言实现顺序队列
    纯C语言实现链队
    纯C语言实现链栈
  • 原文地址:https://www.cnblogs.com/botaoJava/p/13866954.html
Copyright © 2020-2023  润新知