|
|
|
@ -72,12 +72,11 @@ public class ThingsboardSecurityConfiguration { |
|
|
|
public static final String JWT_TOKEN_HEADER_PARAM_V2 = "Authorization"; |
|
|
|
public static final String JWT_TOKEN_QUERY_PARAM = "token"; |
|
|
|
|
|
|
|
public static final String WEBJARS_ENTRY_POINT = "/webjars/**"; |
|
|
|
public static final String DEVICE_API_ENTRY_POINT = "/api/v1/**"; |
|
|
|
public static final String FORM_BASED_LOGIN_ENTRY_POINT = "/api/auth/login"; |
|
|
|
public static final String PUBLIC_LOGIN_ENTRY_POINT = "/api/auth/login/public"; |
|
|
|
public static final String TOKEN_REFRESH_ENTRY_POINT = "/api/auth/token"; |
|
|
|
protected static final String[] NON_TOKEN_BASED_AUTH_ENTRY_POINTS = new String[] {"/index.html", "/assets/**", "/static/**", "/api/noauth/**", "/webjars/**", "/api/license/**", "/api/images/public/**"}; |
|
|
|
protected static final String[] NON_TOKEN_BASED_AUTH_ENTRY_POINTS = new String[]{"/index.html", "/assets/**", "/static/**", "/api/noauth/**", "/webjars/**", "/api/license/**", "/api/images/public/**"}; |
|
|
|
public static final String TOKEN_BASED_AUTH_ENTRY_POINT = "/api/**"; |
|
|
|
public static final String WS_ENTRY_POINT = "/api/ws/**"; |
|
|
|
public static final String MAIL_OAUTH2_PROCESSING_ENTRY_POINT = "/api/admin/mail/oauth2/code"; |
|
|
|
@ -153,7 +152,7 @@ public class ThingsboardSecurityConfiguration { |
|
|
|
protected JwtTokenAuthenticationProcessingFilter buildJwtTokenAuthenticationProcessingFilter() throws Exception { |
|
|
|
List<String> pathsToSkip = new ArrayList<>(Arrays.asList(NON_TOKEN_BASED_AUTH_ENTRY_POINTS)); |
|
|
|
pathsToSkip.addAll(Arrays.asList(WS_ENTRY_POINT, TOKEN_REFRESH_ENTRY_POINT, FORM_BASED_LOGIN_ENTRY_POINT, |
|
|
|
PUBLIC_LOGIN_ENTRY_POINT, DEVICE_API_ENTRY_POINT, WEBJARS_ENTRY_POINT, MAIL_OAUTH2_PROCESSING_ENTRY_POINT, |
|
|
|
PUBLIC_LOGIN_ENTRY_POINT, DEVICE_API_ENTRY_POINT, MAIL_OAUTH2_PROCESSING_ENTRY_POINT, |
|
|
|
DEVICE_CONNECTIVITY_CERTIFICATE_DOWNLOAD_ENTRY_POINT)); |
|
|
|
SkipPathRequestMatcher matcher = new SkipPathRequestMatcher(pathsToSkip, TOKEN_BASED_AUTH_ENTRY_POINT); |
|
|
|
JwtTokenAuthenticationProcessingFilter filter |
|
|
|
@ -201,7 +200,31 @@ public class ThingsboardSecurityConfiguration { |
|
|
|
} |
|
|
|
|
|
|
|
@Bean |
|
|
|
SecurityFilterChain filterChain(HttpSecurity http) throws Exception { |
|
|
|
@Order(1) |
|
|
|
public SecurityFilterChain noAuthFilterChain(HttpSecurity http) throws Exception { |
|
|
|
http.headers(headers -> headers |
|
|
|
.cacheControl(config -> {}) |
|
|
|
.frameOptions(config -> {}).disable()) |
|
|
|
.cors(cors -> {}) |
|
|
|
.csrf(AbstractHttpConfigurer::disable) |
|
|
|
.exceptionHandling(config -> {}) |
|
|
|
.securityMatchers(config -> config |
|
|
|
.requestMatchers( |
|
|
|
DEVICE_API_ENTRY_POINT, // Device HTTP Transport API
|
|
|
|
FORM_BASED_LOGIN_ENTRY_POINT, // Login end-point
|
|
|
|
PUBLIC_LOGIN_ENTRY_POINT, // Public login end-point
|
|
|
|
TOKEN_REFRESH_ENTRY_POINT, // Token refresh end-point
|
|
|
|
MAIL_OAUTH2_PROCESSING_ENTRY_POINT, // Mail oauth2 code processing url
|
|
|
|
DEVICE_CONNECTIVITY_CERTIFICATE_DOWNLOAD_ENTRY_POINT, // Device connectivity certificate (public)
|
|
|
|
WS_ENTRY_POINT) // WebSocket API End-points
|
|
|
|
.requestMatchers(NON_TOKEN_BASED_AUTH_ENTRY_POINTS)) // static resources, user activation and password reset end-points
|
|
|
|
.authorizeHttpRequests(config -> config.anyRequest().permitAll()); |
|
|
|
return http.build(); |
|
|
|
} |
|
|
|
|
|
|
|
@Bean |
|
|
|
@Order(2) |
|
|
|
SecurityFilterChain authFilterChain(HttpSecurity http) throws Exception { |
|
|
|
http.headers(headers -> headers |
|
|
|
.cacheControl(config -> {}) |
|
|
|
.frameOptions(config -> {}).disable()) |
|
|
|
@ -209,19 +232,8 @@ public class ThingsboardSecurityConfiguration { |
|
|
|
.csrf(AbstractHttpConfigurer::disable) |
|
|
|
.exceptionHandling(config -> {}) |
|
|
|
.sessionManagement(config -> config.sessionCreationPolicy(SessionCreationPolicy.STATELESS)) |
|
|
|
.authorizeHttpRequests(config -> config |
|
|
|
.requestMatchers(WEBJARS_ENTRY_POINT).permitAll() // Webjars
|
|
|
|
.requestMatchers(DEVICE_API_ENTRY_POINT).permitAll() // Device HTTP Transport API
|
|
|
|
.requestMatchers(FORM_BASED_LOGIN_ENTRY_POINT).permitAll() // Login end-point
|
|
|
|
.requestMatchers(PUBLIC_LOGIN_ENTRY_POINT).permitAll() // Public login end-point
|
|
|
|
.requestMatchers(TOKEN_REFRESH_ENTRY_POINT).permitAll() // Token refresh end-point
|
|
|
|
.requestMatchers(MAIL_OAUTH2_PROCESSING_ENTRY_POINT).permitAll() // Mail oauth2 code processing url
|
|
|
|
.requestMatchers(DEVICE_CONNECTIVITY_CERTIFICATE_DOWNLOAD_ENTRY_POINT).permitAll() // Device connectivity certificate (public)
|
|
|
|
.requestMatchers(NON_TOKEN_BASED_AUTH_ENTRY_POINTS).permitAll() // static resources, user activation and password reset end-points
|
|
|
|
.requestMatchers(WS_ENTRY_POINT).permitAll() // Protected WebSocket API End-points
|
|
|
|
.requestMatchers(TOKEN_BASED_AUTH_ENTRY_POINT).authenticated()) // Protected API End-points
|
|
|
|
.formLogin(form -> form |
|
|
|
.loginPage("/login").permitAll()) |
|
|
|
.securityMatcher(TOKEN_BASED_AUTH_ENTRY_POINT) // Protected API End-points
|
|
|
|
.authorizeHttpRequests(config -> config.anyRequest().authenticated()) |
|
|
|
.exceptionHandling(config -> config.accessDeniedHandler(restAccessDeniedHandler)) |
|
|
|
.addFilterBefore(buildRestLoginProcessingFilter(), UsernamePasswordAuthenticationFilter.class) |
|
|
|
.addFilterBefore(buildRestPublicLoginProcessingFilter(), UsernamePasswordAuthenticationFilter.class) |
|
|
|
|