Class AuthorizeHttpRequestsConfigurer
java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.AuthorizeHttpRequestsConfigurer
The authorization rules of a chain: which requests need what.
http.authorizeHttpRequests(auth -> auth
.requestMatchers("/", "/css/**").permitAll()
.requestMatchers("/admin/**").hasRole("ADMIN")
.requestMatchers(AntPathRequestMatcher.antMatcher("DELETE", "/api/**"))
.hasAuthority("api:delete")
.anyRequest().authenticated());
The rules are asked in the order they are written and the first that matches decides. A request no rule matches is denied.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionfinal classWhere rules are added: pick the requests, then say what they need.final classWhat the chosen requests need. -
Method Summary
Modifier and TypeMethodDescriptionvoidconfigure(HttpSecurity http) Adds this part's filters; nothing by default.The rules, to add to.Methods inherited from class SecurityConfigurer
disable, getBuilder, init
-
Method Details
-
getRegistry
The rules, to add to. -
configure
Description copied from class:SecurityConfigurerAdds this part's filters; nothing by default.- Overrides:
configurein classSecurityConfigurer
-