Class SecurityConfigurer

java.lang.Object
com.codename1.backend.security.SecurityConfigurer
Direct Known Subclasses:
AnonymousConfigurer, ApiKeyConfigurer, AuthorizationServerConfigurer, AuthorizeHttpRequestsConfigurer, CsrfConfigurer, ExceptionHandlingConfigurer, FormLoginConfigurer, HeadersConfigurer, HttpBasicConfigurer, LogoutConfigurer, MfaConfigurer, OAuth2LoginConfigurer, OAuth2ResourceServerConfigurer, RateLimitConfigurer, RememberMeConfigurer, RequestCacheConfigurer, SecurityContextConfigurer, SessionManagementConfigurer, WebAuthnConfigurer

public abstract class SecurityConfigurer extends Object

One configurable part of an HttpSecurity: form login, CSRF protection, the authorization rules. The built-in parts are these, and so is anything an application or a library adds with HttpSecurity.with(C, Customizer).

When the chain is built every configurer's init(HttpSecurity) runs, then every one's configure(HttpSecurity): init is where a part tells the others about itself -- an entry point, a path that must stay open -- and configure is where it adds its filters.

  • Constructor Details

    • SecurityConfigurer

      public SecurityConfigurer()
  • Method Details

    • getBuilder

      protected final HttpSecurity getBuilder()
      The HttpSecurity this configurer was applied to.
    • init

      public void init(HttpSecurity http)
      Shares what other parts need to know; nothing by default.
    • configure

      public void configure(HttpSecurity http)
      Adds this part's filters; nothing by default.
    • disable

      public HttpSecurity disable()
      Takes this part out of the chain: http.csrf(csrf -> csrf.disable()).