3 changed files with 48 additions and 0 deletions
@ -0,0 +1,44 @@ |
|||
/** |
|||
* Copyright © 2016-2023 The Thingsboard Authors |
|||
* |
|||
* Licensed under the Apache License, Version 2.0 (the "License"); |
|||
* you may not use this file except in compliance with the License. |
|||
* You may obtain a copy of the License at |
|||
* |
|||
* http://www.apache.org/licenses/LICENSE-2.0
|
|||
* |
|||
* Unless required by applicable law or agreed to in writing, software |
|||
* distributed under the License is distributed on an "AS IS" BASIS, |
|||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|||
* See the License for the specific language governing permissions and |
|||
* limitations under the License. |
|||
*/ |
|||
package org.thingsboard.server.config; |
|||
|
|||
import org.springframework.boot.autoconfigure.condition.ConditionalOnExpression; |
|||
import org.springframework.boot.autoconfigure.security.SecurityProperties; |
|||
import org.springframework.context.annotation.Bean; |
|||
import org.springframework.context.annotation.Configuration; |
|||
import org.springframework.core.annotation.Order; |
|||
import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity; |
|||
import org.springframework.security.config.annotation.web.builders.HttpSecurity; |
|||
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; |
|||
import org.springframework.security.web.SecurityFilterChain; |
|||
|
|||
@Configuration |
|||
@EnableWebSecurity |
|||
@EnableGlobalMethodSecurity(prePostEnabled = true) |
|||
@Order(SecurityProperties.BASIC_AUTH_ORDER) |
|||
@ConditionalOnExpression("'${service.type:null}'=='tb-rule-engine'") |
|||
public class TbRuleEngineSecurityConfiguration { |
|||
|
|||
@Bean |
|||
SecurityFilterChain filterChain(HttpSecurity http) throws Exception { |
|||
http.headers().cacheControl().and().frameOptions().disable() |
|||
.and().cors().and().csrf().disable() |
|||
.authorizeRequests() |
|||
.antMatchers("/actuator/prometheus").permitAll() |
|||
.anyRequest().authenticated(); |
|||
return http.build(); |
|||
} |
|||
} |
|||
Loading…
Reference in new issue