ResourceServerConfig.java 2.0 KB

12345678910111213141516171819202122232425262728293031323334353637383940
  1. package com.keao.edu.user.config;
  2. import org.springframework.beans.factory.annotation.Autowired;
  3. import org.springframework.context.annotation.Configuration;
  4. import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity;
  5. import org.springframework.security.config.annotation.web.builders.HttpSecurity;
  6. import org.springframework.security.oauth2.config.annotation.web.configuration.EnableResourceServer;
  7. import org.springframework.security.oauth2.config.annotation.web.configuration.ResourceServerConfigurerAdapter;
  8. import org.springframework.security.oauth2.config.annotation.web.configurers.ResourceServerSecurityConfigurer;
  9. import com.keao.edu.common.security.BaseAccessDeniedHandler;
  10. import com.keao.edu.common.security.BaseAuthenticationEntryPoint;
  11. @Configuration
  12. @EnableResourceServer
  13. @EnableGlobalMethodSecurity(prePostEnabled = true)
  14. public class ResourceServerConfig extends ResourceServerConfigurerAdapter {
  15. @Autowired
  16. private BaseAccessDeniedHandler baseAccessDeniedHandler;
  17. @Autowired
  18. private BaseAuthenticationEntryPoint baseAuthenticationEntryPoint;
  19. @Override
  20. public void configure(HttpSecurity http) throws Exception {
  21. http.authorizeRequests()
  22. .antMatchers("/task/*","/v2/api-docs", "/su/**", "/student/apply", "/examRegistration/ocr", "/examOrder/paymentResult",
  23. "/examOrder/notify","/examinationBasic/getInfo","/examOrder/executePayment","/examOrder/pageList","/studentExamResult/recordSync")
  24. .permitAll()
  25. .anyRequest().authenticated().and().csrf().disable().exceptionHandling().accessDeniedHandler(baseAccessDeniedHandler)
  26. .authenticationEntryPoint(baseAuthenticationEntryPoint).and();
  27. }
  28. @Override
  29. public void configure(ResourceServerSecurityConfigurer resources) throws Exception {
  30. resources.authenticationEntryPoint(baseAuthenticationEntryPoint).accessDeniedHandler(baseAccessDeniedHandler);
  31. }
  32. }