• Post Reply Bookmark Topic Watch Topic
  • New Topic
programming forums Java Mobile Certification Databases Caching Books Engineering Micro Controllers OS Languages Paradigms IDEs Build Tools Frameworks Application Servers Open Source This Site Careers Other all forums
this forum made possible by our volunteer staff, including ...
Marshals:
  • Campbell Ritchie
  • Liutauras Vilda
  • Bear Bibeault
  • Paul Clapham
  • Jeanne Boyarsky
Sheriffs:
  • Devaka Cooray
  • Junilu Lacar
  • Tim Cooke
Saloon Keepers:
  • Tim Moores
  • Ron McLeod
  • Tim Holloway
  • Claude Moore
  • Stephan van Hulst
Bartenders:
  • Winston Gutkowski
  • Carey Brown
  • Frits Walraven

Spring 5 antMatcher not working as expected  RSS feed

 
Bartender
Posts: 1649
17
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Hello,

I have a simple testing authentication set up, but it's allowing any user role to access the "hello" class. I'm using an online example as my learning point and the author didn't get it working correctly either...

Here's the override for configure:

 

But the URL using the user = demo (and admin role), still gets to the page: localhost:8088/rest/hello

I've tried various combinations of asterisks with the .antMatchers() method above, but I can't get the security to respect only the user role.

To get the password stuff to work at all, I also had to refactor the online example to use a Password encoder.

Thanks in advance,

-- mike

 
I RELEASE YOU! (for now .... ) Feel free to peruse this tiny ad:
Become a Java guru with IntelliJ IDEA
https://www.jetbrains.com/idea/
  • Post Reply Bookmark Topic Watch Topic
  • New Topic
Boost this thread!