This commit combines security autoconfigurations for management endpoints and the rest of the application. By default, if Spring Security is on the classpath, it turns on @EnableWebSecurity. In the presence of another WebSecurityConfigurerAdapter this backs off completely. A default AuthenticationManager is also provided with a user and generated password. This can be turned off by specifying a bean of type AuthenticationManager, AuthenticationProvider or UserDetailsService. Closes gh-7958
18 lines
633 B
Java
18 lines
633 B
Java
package sample.secure.oauth2;
|
|
|
|
import org.springframework.context.annotation.Configuration;
|
|
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
|
|
import org.springframework.security.config.annotation.authentication.configurers.GlobalAuthenticationConfigurerAdapter;
|
|
|
|
/**
|
|
* @author Madhura Bhave
|
|
*/
|
|
@Configuration
|
|
public class AuthenticationConfiguration extends GlobalAuthenticationConfigurerAdapter {
|
|
|
|
@Override
|
|
public void init(AuthenticationManagerBuilder auth) throws Exception {
|
|
auth.inMemoryAuthentication().withUser("greg").password("turnquist").roles("read");
|
|
}
|
|
}
|