Use securityMatcher() and authorizeHttpRequests()

Closes gh-922
This commit is contained in:
Joe Grandja
2022-10-22 06:00:16 -04:00
parent 411bf63bc3
commit 64d26a42a0
17 changed files with 70 additions and 70 deletions

View File

@@ -83,8 +83,8 @@ public class JwtUserInfoMapperSecurityConfig {
) )
); );
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests((authorize) -> authorize .authorizeHttpRequests((authorize) -> authorize
.anyRequest().authenticated() .anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))

View File

@@ -63,9 +63,9 @@ public class OAuth2AuthorizationServerConfiguration {
.getEndpointsMatcher(); .getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.apply(authorizationServerConfigurer); .apply(authorizationServerConfigurer);

View File

@@ -843,9 +843,9 @@ public class OAuth2AuthorizationCodeGrantTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.securityContext(securityContext -> .securityContext(securityContext ->
@@ -905,9 +905,9 @@ public class OAuth2AuthorizationCodeGrantTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.apply(authorizationServerConfigurer); .apply(authorizationServerConfigurer);
@@ -938,9 +938,9 @@ public class OAuth2AuthorizationCodeGrantTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.apply(authorizationServerConfigurer); .apply(authorizationServerConfigurer);
@@ -1029,9 +1029,9 @@ public class OAuth2AuthorizationCodeGrantTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.apply(authorizationServerConfigurer); .apply(authorizationServerConfigurer);

View File

@@ -178,9 +178,9 @@ public class OAuth2AuthorizationServerMetadataTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)); .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher));

View File

@@ -415,9 +415,9 @@ public class OAuth2ClientCredentialsGrantTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.apply(authorizationServerConfigurer); .apply(authorizationServerConfigurer);
@@ -447,9 +447,9 @@ public class OAuth2ClientCredentialsGrantTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.apply(authorizationServerConfigurer); .apply(authorizationServerConfigurer);

View File

@@ -519,9 +519,9 @@ public class OAuth2TokenIntrospectionTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.apply(authorizationServerConfigurer); .apply(authorizationServerConfigurer);

View File

@@ -339,9 +339,9 @@ public class OAuth2TokenRevocationTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.apply(authorizationServerConfigurer); .apply(authorizationServerConfigurer);

View File

@@ -366,9 +366,9 @@ public class OidcClientRegistrationTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt) .oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt)

View File

@@ -235,9 +235,9 @@ public class OidcProviderConfigurationTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)); .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher));

View File

@@ -367,9 +367,9 @@ public class OidcTests {
RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher(); RequestMatcher endpointsMatcher = authorizationServerConfigurer.getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)); .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher));

View File

@@ -280,9 +280,9 @@ public class OidcUserInfoTests {
// @formatter:off // @formatter:off
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt) .oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt)
@@ -311,9 +311,9 @@ public class OidcUserInfoTests {
// @formatter:off // @formatter:off
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt) .oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt)
@@ -338,9 +338,9 @@ public class OidcUserInfoTests {
// @formatter:off // @formatter:off
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt) .oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt)

View File

@@ -67,9 +67,9 @@ public class AuthorizationServerConfig {
.getEndpointsMatcher(); .getEndpointsMatcher();
http http
.requestMatcher(endpointsMatcher) .securityMatcher(endpointsMatcher)
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher)) .csrf(csrf -> csrf.ignoringRequestMatchers(endpointsMatcher))
.exceptionHandling(exceptions -> .exceptionHandling(exceptions ->

View File

@@ -1,5 +1,5 @@
/* /*
* Copyright 2020-2021 the original author or authors. * Copyright 2020-2022 the original author or authors.
* *
* Licensed under the Apache License, Version 2.0 (the "License"); * Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License. * you may not use this file except in compliance with the License.
@@ -36,8 +36,8 @@ public class DefaultSecurityConfig {
@Bean @Bean
SecurityFilterChain defaultSecurityFilterChain(HttpSecurity http) throws Exception { SecurityFilterChain defaultSecurityFilterChain(HttpSecurity http) throws Exception {
http http
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.formLogin(withDefaults()); .formLogin(withDefaults());
return http.build(); return http.build();

View File

@@ -1,5 +1,5 @@
/* /*
* Copyright 2020-2021 the original author or authors. * Copyright 2020-2022 the original author or authors.
* *
* Licensed under the Apache License, Version 2.0 (the "License"); * Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License. * you may not use this file except in compliance with the License.
@@ -37,8 +37,8 @@ public class DefaultSecurityConfig {
@Bean @Bean
SecurityFilterChain defaultSecurityFilterChain(HttpSecurity http) throws Exception { SecurityFilterChain defaultSecurityFilterChain(HttpSecurity http) throws Exception {
http http
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.formLogin(withDefaults()); .formLogin(withDefaults());
return http.build(); return http.build();

View File

@@ -41,9 +41,9 @@ public class DefaultSecurityConfig {
FederatedIdentityConfigurer federatedIdentityConfigurer = new FederatedIdentityConfigurer() FederatedIdentityConfigurer federatedIdentityConfigurer = new FederatedIdentityConfigurer()
.oauth2UserHandler(new UserRepositoryOAuth2UserHandler()); .oauth2UserHandler(new UserRepositoryOAuth2UserHandler());
http http
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests authorize
.mvcMatchers("/assets/**", "/webjars/**", "/login").permitAll() .requestMatchers("/assets/**", "/webjars/**", "/login").permitAll()
.anyRequest().authenticated() .anyRequest().authenticated()
) )
.formLogin(Customizer.withDefaults()) .formLogin(Customizer.withDefaults())

View File

@@ -1,5 +1,5 @@
/* /*
* Copyright 2020-2021 the original author or authors. * Copyright 2020-2022 the original author or authors.
* *
* Licensed under the Apache License, Version 2.0 (the "License"); * Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License. * you may not use this file except in compliance with the License.
@@ -32,15 +32,15 @@ public class SecurityConfig {
@Bean @Bean
WebSecurityCustomizer webSecurityCustomizer() { WebSecurityCustomizer webSecurityCustomizer() {
return (web) -> web.ignoring().antMatchers("/webjars/**"); return (web) -> web.ignoring().requestMatchers("/webjars/**");
} }
// @formatter:off // @formatter:off
@Bean @Bean
SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
http http
.authorizeRequests(authorizeRequests -> .authorizeHttpRequests(authorize ->
authorizeRequests.anyRequest().authenticated() authorize.anyRequest().authenticated()
) )
.oauth2Login(oauth2Login -> .oauth2Login(oauth2Login ->
oauth2Login.loginPage("/oauth2/authorization/messaging-client-oidc")) oauth2Login.loginPage("/oauth2/authorization/messaging-client-oidc"))

View File

@@ -1,5 +1,5 @@
/* /*
* Copyright 2020-2021 the original author or authors. * Copyright 2020-2022 the original author or authors.
* *
* Licensed under the Apache License, Version 2.0 (the "License"); * Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License. * you may not use this file except in compliance with the License.
@@ -31,9 +31,9 @@ public class ResourceServerConfig {
@Bean @Bean
SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
http http
.mvcMatcher("/messages/**") .securityMatcher("/messages/**")
.authorizeRequests() .authorizeHttpRequests()
.mvcMatchers("/messages/**").access("hasAuthority('SCOPE_message.read')") .requestMatchers("/messages/**").hasAuthority("SCOPE_message.read")
.and() .and()
.oauth2ResourceServer() .oauth2ResourceServer()
.jwt(); .jwt();