Migrate to Spring Security lambda config
Closes gh-35011
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2012-2022 the original author or authors.
|
||||
* Copyright 2012-2023 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -36,7 +36,7 @@ public class DevProfileSecurityConfiguration {
|
||||
http.securityMatcher(PathRequest.toH2Console());
|
||||
http.authorizeHttpRequests(yourCustomAuthorization());
|
||||
http.csrf((csrf) -> csrf.disable());
|
||||
http.headers((headers) -> headers.frameOptions().sameOrigin());
|
||||
http.headers((headers) -> headers.frameOptions((frame) -> frame.sameOrigin()));
|
||||
return http.build();
|
||||
}
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2012-2022 the original author or authors.
|
||||
* Copyright 2012-2023 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -27,7 +27,7 @@ public class MyOAuthClientConfiguration {
|
||||
@Bean
|
||||
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
|
||||
http.authorizeHttpRequests((requests) -> requests.anyRequest().authenticated());
|
||||
http.oauth2Login((login) -> login.redirectionEndpoint().baseUri("custom-callback"));
|
||||
http.oauth2Login((login) -> login.redirectionEndpoint((endpoint) -> endpoint.baseUri("custom-callback")));
|
||||
return http.build();
|
||||
}
|
||||
|
||||
|
||||
@@ -21,13 +21,15 @@ import org.springframework.context.annotation.Configuration;
|
||||
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
|
||||
import org.springframework.security.web.SecurityFilterChain;
|
||||
|
||||
import static org.springframework.security.config.Customizer.withDefaults;
|
||||
|
||||
@Configuration(proxyBeanMethods = false)
|
||||
public class MySamlRelyingPartyConfiguration {
|
||||
|
||||
@Bean
|
||||
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
|
||||
http.authorizeHttpRequests().anyRequest().authenticated();
|
||||
http.saml2Login();
|
||||
http.authorizeHttpRequests((requests) -> requests.anyRequest().authenticated());
|
||||
http.saml2Login(withDefaults());
|
||||
http.saml2Logout((saml2) -> saml2.logoutRequest((request) -> request.logoutUrl("/SLOService.saml2"))
|
||||
.logoutResponse((response) -> response.logoutUrl("/SLOService.saml2")));
|
||||
return http.build();
|
||||
|
||||
@@ -19,6 +19,7 @@ package org.springframework.boot.docs.actuator.endpoints.security.typical
|
||||
import org.springframework.boot.actuate.autoconfigure.security.servlet.EndpointRequest
|
||||
import org.springframework.context.annotation.Bean
|
||||
import org.springframework.context.annotation.Configuration
|
||||
import org.springframework.security.config.Customizer.withDefaults
|
||||
import org.springframework.security.config.annotation.web.builders.HttpSecurity
|
||||
import org.springframework.security.web.SecurityFilterChain
|
||||
|
||||
@@ -30,7 +31,7 @@ class MySecurityConfiguration {
|
||||
http.securityMatcher(EndpointRequest.toAnyEndpoint()).authorizeHttpRequests { requests ->
|
||||
requests.anyRequest().hasRole("ENDPOINT_ADMIN")
|
||||
}
|
||||
http.httpBasic()
|
||||
http.httpBasic(withDefaults())
|
||||
return http.build()
|
||||
}
|
||||
|
||||
|
||||
@@ -33,8 +33,8 @@ class DevProfileSecurityConfiguration {
|
||||
@Order(Ordered.HIGHEST_PRECEDENCE)
|
||||
fun h2ConsoleSecurityFilterChain(http: HttpSecurity): SecurityFilterChain {
|
||||
return http.authorizeHttpRequests(yourCustomAuthorization())
|
||||
.csrf().disable()
|
||||
.headers().frameOptions().sameOrigin().and()
|
||||
.csrf { csrf -> csrf.disable() }
|
||||
.headers { headers -> headers.frameOptions { frameOptions -> frameOptions.sameOrigin() } }
|
||||
.build()
|
||||
}
|
||||
|
||||
|
||||
@@ -27,7 +27,7 @@ class MySecurityConfig {
|
||||
@Bean
|
||||
fun securityFilterChain(http: HttpSecurity): SecurityFilterChain {
|
||||
// Customize the application security ...
|
||||
http.requiresChannel().anyRequest().requiresSecure()
|
||||
http.requiresChannel { requests -> requests.anyRequest().requiresSecure() }
|
||||
return http.build()
|
||||
}
|
||||
|
||||
|
||||
@@ -26,8 +26,8 @@ class MyOAuthClientConfiguration {
|
||||
|
||||
@Bean
|
||||
fun securityFilterChain(http: HttpSecurity): SecurityFilterChain {
|
||||
http.authorizeHttpRequests().anyRequest().authenticated()
|
||||
http.oauth2Login().redirectionEndpoint().baseUri("custom-callback")
|
||||
http.authorizeHttpRequests { requests -> requests.anyRequest().authenticated() }
|
||||
http.oauth2Login { login -> login.redirectionEndpoint { redirectionEndpoint -> redirectionEndpoint.baseUri("custom-callback") } }
|
||||
return http.build()
|
||||
}
|
||||
|
||||
|
||||
@@ -19,6 +19,8 @@ package org.springframework.boot.docs.web.security.springwebflux
|
||||
import org.springframework.boot.autoconfigure.security.reactive.PathRequest
|
||||
import org.springframework.context.annotation.Bean
|
||||
import org.springframework.context.annotation.Configuration
|
||||
import org.springframework.security.config.Customizer
|
||||
import org.springframework.security.config.Customizer.withDefaults
|
||||
import org.springframework.security.config.web.server.ServerHttpSecurity
|
||||
import org.springframework.security.web.server.SecurityWebFilterChain
|
||||
|
||||
@@ -31,7 +33,7 @@ class MyWebFluxSecurityConfiguration {
|
||||
spec.matchers(PathRequest.toStaticResources().atCommonLocations()).permitAll()
|
||||
spec.pathMatchers("/foo", "/bar").authenticated()
|
||||
}
|
||||
http.formLogin()
|
||||
http.formLogin(withDefaults())
|
||||
return http.build()
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user