@@ -61,28 +61,57 @@ public SecurityFilterChain filterChain(HttpSecurity http, MvcRequestMatcher.Buil
6161 .authorizeHttpRequests (
6262 authz ->
6363 // prettier-ignore
64- authz
65- .requestMatchers (mvc .pattern ("/index.html" ), mvc .pattern ("/*.js" ), mvc .pattern ("/*.txt" ), mvc .pattern ("/*.json" ), mvc .pattern ("/*.map" ), mvc .pattern ("/*.css" )).permitAll ()
66- .requestMatchers (mvc .pattern ("/*.ico" ), mvc .pattern ("/*.png" ), mvc .pattern ("/*.svg" ), mvc .pattern ("/*.webapp" )).permitAll ()
67- .requestMatchers (mvc .pattern ("/app/**" )).permitAll ()
68- .requestMatchers (mvc .pattern ("/i18n/**" )).permitAll ()
69- .requestMatchers (mvc .pattern ("/content/**" )).permitAll ()
70- .requestMatchers (mvc .pattern ("/swagger-ui/**" )).permitAll ()
71- .requestMatchers (mvc .pattern (HttpMethod .POST , "/api/authenticate" )).permitAll ()
72- .requestMatchers (mvc .pattern (HttpMethod .GET , "/api/authenticate" )).permitAll ()
73- .requestMatchers (mvc .pattern ("/api/register" )).permitAll ()
74- .requestMatchers (mvc .pattern ("/api/activate" )).permitAll ()
75- .requestMatchers (mvc .pattern ("/api/account/reset-password/init" )).permitAll ()
76- .requestMatchers (mvc .pattern ("/api/account/reset-password/finish" )).permitAll ()
77- .requestMatchers (mvc .pattern ("/api/admin/**" )).hasAuthority (AuthoritiesConstants .ADMIN )
78- .requestMatchers (mvc .pattern ("/api/**" )).authenticated ()
79- .requestMatchers (mvc .pattern ("/websocket/**" )).authenticated ()
80- .requestMatchers (mvc .pattern ("/v3/api-docs/**" )).hasAuthority (AuthoritiesConstants .ADMIN )
81- .requestMatchers (mvc .pattern ("/management/health" )).permitAll ()
82- .requestMatchers (mvc .pattern ("/management/health/**" )).permitAll ()
83- .requestMatchers (mvc .pattern ("/management/info" )).permitAll ()
84- .requestMatchers (mvc .pattern ("/management/prometheus" )).permitAll ()
85- .requestMatchers (mvc .pattern ("/management/**" )).hasAuthority (AuthoritiesConstants .ADMIN )
64+ authz
65+ .requestMatchers (mvc .pattern ("/index.html" ),
66+ mvc .pattern ("/*.js" ),
67+ mvc .pattern ("/*.txt" ),
68+ mvc .pattern ("/*.json" ),
69+ mvc .pattern ("/*.map" ),
70+ mvc .pattern ("/*.css" ))
71+ .permitAll ()
72+ .requestMatchers (mvc .pattern ("/*.ico" ),
73+ mvc .pattern ("/*.png" ),
74+ mvc .pattern ("/*.svg" ),
75+ mvc .pattern ("/*.webapp" ))
76+ .permitAll ()
77+ .requestMatchers (mvc .pattern ("/app/**" )).permitAll ()
78+ .requestMatchers (mvc .pattern ("/i18n/**" )).permitAll ()
79+ .requestMatchers (mvc .pattern ("/content/**" )).permitAll ()
80+ .requestMatchers (mvc .pattern ("/swagger-ui/**" ))
81+ .permitAll ()
82+ .requestMatchers (mvc .pattern (HttpMethod .POST ,
83+ "/api/authenticate" ))
84+ .permitAll ()
85+ .requestMatchers (mvc .pattern (HttpMethod .GET ,
86+ "/api/authenticate" ))
87+ .permitAll ()
88+ .requestMatchers (mvc .pattern ("/api/register" ))
89+ .permitAll ()
90+ .requestMatchers (mvc .pattern ("/api/activate" ))
91+ .permitAll ()
92+ .requestMatchers (mvc .pattern (
93+ "/api/account/reset-password/init" ))
94+ .permitAll ()
95+ .requestMatchers (mvc .pattern (
96+ "/api/account/reset-password/finish" ))
97+ .permitAll ()
98+ .requestMatchers (mvc .pattern ("/api/admin/**" ))
99+ .hasAuthority (AuthoritiesConstants .ADMIN )
100+ .requestMatchers (mvc .pattern ("/api/**" )).authenticated ()
101+ .requestMatchers (mvc .pattern ("/websocket/**" ))
102+ .authenticated ()
103+ .requestMatchers (mvc .pattern ("/v3/api-docs/**" ))
104+ .hasAuthority (AuthoritiesConstants .ADMIN )
105+ .requestMatchers (mvc .pattern ("/management/health" ))
106+ .permitAll ()
107+ .requestMatchers (mvc .pattern ("/management/health/**" ))
108+ .permitAll ()
109+ .requestMatchers (mvc .pattern ("/management/info" ))
110+ .permitAll ()
111+ .requestMatchers (mvc .pattern ("/management/prometheus" ))
112+ .permitAll ()
113+ .requestMatchers (mvc .pattern ("/management/**" ))
114+ .hasAuthority (AuthoritiesConstants .ADMIN )
86115 )
87116 .sessionManagement (session -> session .sessionCreationPolicy (SessionCreationPolicy .STATELESS ))
88117 .exceptionHandling (
0 commit comments