Provide EndpointRequest for WebFlux-based Security
Closes gh-11022
This commit is contained in:
@@ -2882,6 +2882,17 @@ messages. Otherwise, the default password is not printed.
|
||||
You can change the username and password by providing a `spring.security.user.name` and
|
||||
`spring.security.user.password`.
|
||||
|
||||
The basic features you get by default in a web application are:
|
||||
|
||||
* A `UserDetailsService` (or `ReactiveUserDetailsService` in case of a WebFlux application)
|
||||
bean with in-memory store and a single user with a generated password (see
|
||||
{dc-spring-boot}/autoconfigure/security/SecurityProperties.User.html[`SecurityProperties.User`]
|
||||
for the properties of the user).
|
||||
* Form-based login or HTTP Basic security (depending on Content-Type) for the entire
|
||||
application (including actuator endpoints if actuator is on the classpath).
|
||||
|
||||
== MVC Security
|
||||
|
||||
The default security configuration is implemented in `SecurityAutoConfiguration` and in
|
||||
the classes imported from there (`SpringBootWebSecurityConfiguration` for web security
|
||||
and `AuthenticationManagerConfiguration` for authentication configuration, which is also
|
||||
@@ -2894,15 +2905,6 @@ To also switch off the authentication manager configuration, you can add a bean
|
||||
There are several secure applications in the {github-code}/spring-boot-samples/[Spring
|
||||
Boot samples] to get you started with common use cases.
|
||||
|
||||
The basic features you get by default in a web application are:
|
||||
|
||||
* A `UserDetailsService` bean with in-memory store and a single user with a generated
|
||||
password (see
|
||||
{dc-spring-boot}/autoconfigure/security/SecurityProperties.User.html[`SecurityProperties.User`]
|
||||
for the properties of the user).
|
||||
* Form-based login or HTTP Basic security (depending on Content-Type) for the entire
|
||||
application (including actuator endpoints if actuator is on the classpath).
|
||||
|
||||
Access rules can be overridden by adding a custom `WebSecurityConfigurerAdapter`. Spring
|
||||
Boot provides convenience methods that can be used to override access rules for actuator
|
||||
endpoints and static resources. `EndpointRequest` can be used to create a `RequestMatcher`
|
||||
@@ -2910,7 +2912,22 @@ that is based on the `management.endpoints.web.base-path` property.
|
||||
`StaticResourceRequest` can be used to create a `RequestMatcher` for static resources in
|
||||
commonly used locations.
|
||||
|
||||
== WebFlux Security
|
||||
|
||||
The default security configuration is implemented in `ReactiveSecurityAutoConfiguration` and in
|
||||
the classes imported from there (`WebFluxSecurityConfiguration` for web security
|
||||
and `ReactiveAuthenticationManagerConfiguration` for authentication configuration, which is also
|
||||
relevant in non-web applications). To switch off the default web application security
|
||||
configuration completely, you can add a bean of type `WebFilterChainProxy` (doing
|
||||
so does not disable the authentication manager configuration or Actuator's security).
|
||||
|
||||
To also switch off the authentication manager configuration, you can add a bean of type
|
||||
`ReactiveUserDetailsService` or `ReactiveAuthenticationManager`.
|
||||
|
||||
Access rules can be configured by adding a custom `SecurityWebFilterChain`. Spring
|
||||
Boot provides convenience methods that can be used to override access rules for actuator
|
||||
endpoints and static resources. `EndpointRequest` can be used to create a `ServerWebExchangeMatcher`
|
||||
that is based on the `management.endpoints.web.base-path` property.
|
||||
|
||||
[[boot-features-security-oauth2]]
|
||||
=== OAuth2
|
||||
|
||||
Reference in New Issue
Block a user