Interface SecurityFilterChain

All Known Implementing Classes:
DefaultSecurityFilterChain

public interface SecurityFilterChain

The filters that guard some of a server's requests. An application declares one as a bean, built from the HttpSecurity it is handed:

@Configuration
public class SecurityConfig {
    @Bean
    @Order(1)
    SecurityFilterChain api(HttpSecurity http) {
        http.securityMatcher("/api/**")
            .authorizeHttpRequests(auth -> auth.anyRequest().hasRole("API"))
            .httpBasic(Customizer.withDefaults())
            .csrf(csrf -> csrf.disable());
        return http.build();
    }

    @Bean
    SecurityFilterChain pages(HttpSecurity http) {
        http.authorizeHttpRequests(auth -> auth
                .requestMatchers("/", "/css/**").permitAll()
                .anyRequest().authenticated())
            .formLogin(Customizer.withDefaults());
        return http.build();
    }
}

A request is put to the chains in @Order, and the first whose matches(HttpServer.Request) answers true is the only one that sees it. A request no chain matches is not guarded at all. The server's own endpoints -- management, MCP, the telemetry relay -- are not put to any chain: they keep their own tokens.

  • Method Details