3 changed files with 48 additions and 0 deletions
@ -0,0 +1,44 @@ |
|||||
|
/** |
||||
|
* Copyright © 2016-2023 The Thingsboard Authors |
||||
|
* |
||||
|
* Licensed under the Apache License, Version 2.0 (the "License"); |
||||
|
* you may not use this file except in compliance with the License. |
||||
|
* You may obtain a copy of the License at |
||||
|
* |
||||
|
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
* |
||||
|
* Unless required by applicable law or agreed to in writing, software |
||||
|
* distributed under the License is distributed on an "AS IS" BASIS, |
||||
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
||||
|
* See the License for the specific language governing permissions and |
||||
|
* limitations under the License. |
||||
|
*/ |
||||
|
package org.thingsboard.server.config; |
||||
|
|
||||
|
import org.springframework.boot.autoconfigure.condition.ConditionalOnExpression; |
||||
|
import org.springframework.boot.autoconfigure.security.SecurityProperties; |
||||
|
import org.springframework.context.annotation.Bean; |
||||
|
import org.springframework.context.annotation.Configuration; |
||||
|
import org.springframework.core.annotation.Order; |
||||
|
import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity; |
||||
|
import org.springframework.security.config.annotation.web.builders.HttpSecurity; |
||||
|
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; |
||||
|
import org.springframework.security.web.SecurityFilterChain; |
||||
|
|
||||
|
@Configuration |
||||
|
@EnableWebSecurity |
||||
|
@EnableGlobalMethodSecurity(prePostEnabled = true) |
||||
|
@Order(SecurityProperties.BASIC_AUTH_ORDER) |
||||
|
@ConditionalOnExpression("'${service.type:null}'=='tb-rule-engine'") |
||||
|
public class TbRuleEngineSecurityConfiguration { |
||||
|
|
||||
|
@Bean |
||||
|
SecurityFilterChain filterChain(HttpSecurity http) throws Exception { |
||||
|
http.headers().cacheControl().and().frameOptions().disable() |
||||
|
.and().cors().and().csrf().disable() |
||||
|
.authorizeRequests() |
||||
|
.antMatchers("/actuator/prometheus").permitAll() |
||||
|
.anyRequest().authenticated(); |
||||
|
return http.build(); |
||||
|
} |
||||
|
} |
||||
Loading…
Reference in new issue